What the vulnerability does
01Description
Unauth. IDOR vulnerability leading to PII Disclosure in WooCommerce Stripe Payment Gateway plugin <= 7.4.0 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
What the vulnerability does
Unauth. IDOR vulnerability leading to PII Disclosure in WooCommerce Stripe Payment Gateway plugin <= 7.4.0 versions.
Explanation of Vulnerability in Simple Terms
The WooCommerce Stripe Payment Gateway through version 7.4.0 exposes sensitive payment information to unauthenticated attackers over the network. An attacker can read confidential data without requiring user interaction or special privileges. This affects sites using the vulnerable plugin version to process Stripe payments.
What an attacker can do
Read sensitive payment or customer data without authentication.
Potential impact on your site
Customer payment information or other confidential data may be exposed to attackers.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities