The Stripe for WooCommerce WordPress plugin is missing a capability check on the save() function found in the ~/includes/admin/class-wc-stripe-admin-user-edit.php file that makes it possible for attackers to configure their account to use other site users unique STRIPE identifier and make purchases with their payment accounts. This affects versions 3.0.0 - 3.3.9.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2021-10-04T17:21:49.430265Z

Updated: 2024-09-17T03:55:07.950Z

Reserved: 2021-08-20T00:00:00

Link: CVE-2021-39347

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-10-04T18:15:09.433

Modified: 2021-10-12T22:32:29.467

Link: CVE-2021-39347

cve-icon Redhat

No data.