What the vulnerability does
01Description
Unauthenticated Insecure Direct Object References (IDOR) in Razorpay for WooCommerce <= 4.8.7 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Unauthenticated Insecure Direct Object References (IDOR) in Razorpay for WooCommerce <= 4.8.7 versions.
Explanation of Vulnerability in Simple Terms
The Razorpay for WooCommerce plugin through version 4.8.7 contains an authorization bypass vulnerability in how it handles user-controlled keys. An attacker can modify payment-related parameters to bypass authorization checks and alter transaction data without proper verification. This affects the integrity of payment records but does not expose sensitive data or disrupt service availability.
What an attacker can do
Modify payment transaction details or bypass authorization checks by manipulating user-controlled keys.
Potential impact on your site
Attackers can alter payment records or transaction metadata, potentially causing billing disputes or fraudulent transaction claims.
Conditions required to exploit
Network access to the WooCommerce site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities