The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.7.7. This is due to insufficient verification on the user being supplied during a Stripe checkout through the plugin. This allows unauthenticated attackers to log in as users who have orders, who are typically customers.
History

Tue, 01 Oct 2024 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2023-08-31T05:33:07.144Z

Updated: 2024-10-01T18:01:13.516Z

Reserved: 2023-06-08T12:39:24.512Z

Link: CVE-2023-3162

cve-icon Vulnrichment

Updated: 2024-08-02T06:48:07.784Z

cve-icon NVD

Status : Modified

Published: 2023-08-31T06:15:09.737

Modified: 2024-11-21T08:16:35.813

Link: CVE-2023-3162

cve-icon Redhat

No data.