What the vulnerability does
01Description
Missing Authorization vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue affects WooCommerce Stripe Payment Gateway: from n/a through 7.4.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
What the vulnerability does
Missing Authorization vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue affects WooCommerce Stripe Payment Gateway: from n/a through 7.4.0.
Explanation of Vulnerability in Simple Terms
The WooCommerce Stripe Payment Gateway plugin through version 7.4.0 does not properly validate authorization for certain payment operations. An attacker without authentication can modify payment details or transaction records by sending crafted requests directly to the plugin. This allows unauthorized changes to orders or payment information without requiring a valid user account or admin access.
What an attacker can do
Modify payment details or transaction records without authentication.
Potential impact on your site
Attackers can alter order data or payment information, potentially causing financial loss or order fulfillment errors.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities