What the vulnerability does
01Description
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce GoCardless.This issue affects GoCardless: from n/a through 2.5.6.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
What the vulnerability does
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce GoCardless.This issue affects GoCardless: from n/a through 2.5.6.
Explanation of Vulnerability in Simple Terms
The GoCardless payment plugin for WooCommerce versions up to 2.5.6 exposes sensitive payment information through insufficient access controls. An attacker without authentication can read transaction data and payment details. The vulnerability affects the confidentiality of customer payment records and may impact site availability.
What an attacker can do
Read sensitive payment and transaction data without logging in.
Potential impact on your site
Customer payment information and transaction history exposed to unauthorized access.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities