Impact
An unauthenticated Cross Site Request Forgery vulnerability is present in the FunnelKit Payment Gateway for Stripe WooCommerce plugin versions up to 1.14.0.3. The flaw allows an attacker to forge requests that the plugin will accept as legitimate, potentially causing unintended actions such as modifying payment gateway settings or processing payments on behalf of a legitimate user. This can compromise the integrity and confidentiality of a site’s financial configuration and may expose sensitive transaction data.
Affected Systems
The affected product is the FunnelKit Payment Gateway for Stripe WooCommerce plugin used with WordPress. Versions 1.14.0.3 and earlier are impacted. There are no additional upstream CPE version details provided beyond the maximum affected version stated.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the vulnerability is not listed in the CISA KEV catalog. EPSS data is not available. Based on the description, the likely attack vector is a crafted HTTP request that an attacker can prompt a victim to execute, for example by embedding a malicious link in an email or web page. The flaw does not require authentication, so any user with access to the site’s frontend is a potential target, while an attacker benefits from an untrusted site to trigger the forged request.
OpenCVE Enrichment