What the vulnerability does
01Description
Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions.
Explanation of Vulnerability in Simple Terms
The Piraeus Bank WooCommerce Payment Gateway contains an authentication bypass vulnerability that allows attackers to modify payment transactions without valid credentials. The flaw exists in an alternate authentication path, enabling unauthorized changes to transaction integrity. No user interaction or special privileges are required to exploit this issue.
What an attacker can do
Modify payment transaction data without authentication.
Potential impact on your site
Attackers can alter payment records, potentially causing transaction disputes and revenue loss.
Conditions required to exploit
Network access to the payment gateway; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities