Lucene search

K
wpexploitWpvulndbWPEX-ID:09CE3ADE-80FC-438B-8976-852A273D7C53
HistoryJun 13, 2023 - 12:00 a.m.

WooCommerce Stripe Payment Gateway < 7.4.1 - Unauthenticated PII Disclosure via IDOR

2023-06-1300:00:00
wpvulndb
45
woocommerce
stripe
payment gateway
unauthenticated
pii
disclosure
idor
exploit

0.001 Low

EPSS

Percentile

47.1%

The plugin does not ensure that the order details to be displayed belongs to the user making the request, allows unauthenticated users to access sensitive information about the reorder details such as first/last names, email and address

As unauthenticated, see the source of https://example.com/?pay_for_order=true&order-pay=80 (80 being a valid order number)

0.001 Low

EPSS

Percentile

47.1%

Related for WPEX-ID:09CE3ADE-80FC-438B-8976-852A273D7C53