Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-3162
HistoryAug 31, 2023 - 6:15 a.m.

Authentication flaw

2023-08-3106:15:00
PRIOn knowledge base
www.prio-n.com
7
woocommerce
wordpress
authentication bypass
vulnerability
stripe payment plugin

9.6 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

34.0%

The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.7.7. This is due to insufficient verification on the user being supplied during a Stripe checkout through the plugin. This allows unauthenticated attackers to log in as users who have orders, who are typically customers.

9.6 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

34.0%