Impact
An unauthenticated broken access control flaw in WordPress’s Stripe For WooCommerce plugin allows attackers to bypass authentication checks and perform actions that should be restricted to privileged users. The vulnerability is classified as CWE-862 and can enable attackers to alter payment settings or execute privileged operations, compromising the confidentiality, integrity, or availability of the payment system.
Affected Systems
The affected vendor is Payment Plugins, product Stripe For WooCommerce. Versions of the plugin up to and including 4.0.7 are vulnerable. Any WordPress site using those versions is potentially at risk.
Risk and Exploitability
The CVSS score of 7.5 indicates a moderate to high severity. The EPSS score is <1%, indicating only a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, as the flaw can be triggered by unauthenticated HTTP requests to the WordPress site’s plugin endpoints. An attacker could craft requests that bypass the normal access controls and perform privileged actions.
OpenCVE Enrichment