What the vulnerability does
01Description
Authenticated Arbitrary Settings Update vulnerability in YooMoney ЮKassa для WooCommerce plugin <= 2.3.0 at WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Authenticated Arbitrary Settings Update vulnerability in YooMoney ЮKassa для WooCommerce plugin <= 2.3.0 at WordPress.
Explanation of Vulnerability in Simple Terms
The YooMoney payment plugin for WooCommerce (version 2.3.0 and earlier) contains an access control vulnerability that allows authenticated users with low privileges to read sensitive data, modify site content, or disrupt service. The vulnerability requires a valid WordPress user account but no special interaction. Site administrators should update immediately to a patched version.
What an attacker can do
Read sensitive data, modify site content, or disrupt service with a low-privilege WordPress account.
Potential impact on your site
Any low-privilege user on your site can access payment data, modify orders, or crash the plugin.
Conditions required to exploit
Attacker must have a valid low-privilege WordPress user account (e.g., subscriber or contributor role).
Key dates
External resources
Related vulnerabilities