NA

CVE-2023-4040

Published: 18/08/2023 Updated: 07/11/2023
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the eh_callback_handler function in versions up to, and including, 3.7.9. This makes it possible for unauthenticated malicious users to modify the order status of arbitrary WooCommerce orders.

Vulnerable Product Search on Vulmon Subscribe to Product

webtoffee stripe payment plugin for woocommerce