NA

CVE-2023-3162

Published: 31/08/2023 Updated: 07/11/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.7.7. This is due to insufficient verification on the user being supplied during a Stripe checkout through the plugin. This allows unauthenticated malicious users to log in as users who have orders, who are typically customers.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

webtoffee stripe payment plugin for woocommerce

Exploits

WordPress Stripe Payment Plugin for WooCommerce plugin versions 377 and below suffer from an authentication bypass vulnerability ...