What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue affects WooCommerce Stripe Payment Gateway: from n/a through 7.6.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue affects WooCommerce Stripe Payment Gateway: from n/a through 7.6.0.
Explanation of Vulnerability in Simple Terms
The WooCommerce Stripe Payment Gateway plugin through version 7.6.0 is vulnerable to cross-site request forgery (CSRF) attacks. An attacker can craft a malicious link or page that, when visited by a logged-in site administrator, performs unwanted actions on the payment gateway configuration. This could result in unauthorized changes to payment settings or data integrity issues.
What an attacker can do
Trick an admin into visiting a malicious page that modifies payment gateway settings or causes unintended actions.
Potential impact on your site
Payment gateway configuration could be altered without authorization, potentially disrupting transactions or exposing payment data.
Conditions required to exploit
Admin must be logged in and click a malicious link or visit an attacker-controlled page.
Key dates
External resources
Related vulnerabilities