What the vulnerability does
01Description
Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0.7 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
What the vulnerability does
Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0.7 versions.
Explanation of Vulnerability in Simple Terms
Stripe For WooCommerce versions up to 4.0.7 lack proper authorization checks, allowing unauthenticated attackers to modify payment-related data or settings. An attacker can send network requests without credentials to alter sensitive configuration. Site owners should update immediately to prevent unauthorized changes to payment processing.
What an attacker can do
Modify payment settings or transaction data without logging in.
Potential impact on your site
Attackers can alter payment configuration, potentially redirecting funds or disabling payment processing.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities