What the vulnerability does
01Description
Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pago payments for WooCommerce <= 8.9.0 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pago payments for WooCommerce <= 8.9.0 versions.
Explanation of Vulnerability in Simple Terms
The Mercado Pago payments plugin for WooCommerce versions up to 8.9.0 contains an authorization bypass vulnerability. An attacker can read sensitive payment information by manipulating user-controlled parameters in API requests. No authentication or user interaction is required. Site owners should update to a version newer than 8.9.0 immediately.
What an attacker can do
Read sensitive payment and customer data without authentication.
Potential impact on your site
Customer payment details and transaction records may be exposed to unauthorized access.
Conditions required to exploit
Network access to the site; no authentication required.
Key dates
External resources
Related vulnerabilities