What the vulnerability does
01Description
Subscriber Broken Access Control in ЮKassa для WooCommerce <= 2.16.1 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Subscriber Broken Access Control in ЮKassa для WooCommerce <= 2.16.1 versions.
Explanation of Vulnerability in Simple Terms
The YooMoney payment gateway plugin for WooCommerce versions up to 2.16.1 lacks proper authorization checks on certain functions. A logged-in user with low privileges can modify payment settings or transaction data without proper permission verification. This affects the integrity of payment processing but does not expose sensitive data or disrupt site availability.
What an attacker can do
A logged-in user can modify payment settings or transaction records without proper authorization.
Potential impact on your site
Unauthorized users may alter payment configuration or transaction details, potentially disrupting payment processing or creating fraudulent records.
Conditions required to exploit
Attacker must have a low-privilege account on the WooCommerce site (e.g., customer or subscriber role).
Key dates
External resources
Related vulnerabilities