What the vulnerability does
01Description
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue affects WooCommerce Stripe Payment Gateway: from n/a through 7.6.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
What the vulnerability does
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue affects WooCommerce Stripe Payment Gateway: from n/a through 7.6.1.
Explanation of Vulnerability in Simple Terms
The WooCommerce Stripe Payment Gateway through version 7.6.1 contains an authorization bypass vulnerability that allows attackers to modify payment transactions without authentication. An attacker can intercept or manipulate Stripe payment requests over the network, potentially altering transaction details. This affects any WooCommerce store using the vulnerable plugin version.
What an attacker can do
Modify payment transaction details or bypass payment authorization checks without authentication.
Potential impact on your site
Attackers can alter orders, amounts, or payment status, leading to financial loss and order integrity issues.
Conditions required to exploit
Network access to the WooCommerce store; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities