Lucene search

K
wpvulndbWpvulndbWPVDB-ID:E987660E-C872-4C87-B45B-46A273ADFF16
HistoryAug 18, 2023 - 12:00 a.m.

Stripe Payment < 3.8.0 - Unauthenticated WC Order Status Update

2023-08-1800:00:00
wpscan.com
3
stripe payment
unauthenticated users
woocommerce orders
authorisation
security vulnerability

6.6 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

20.5%

Description The plugin does not have authorisation in its eh_callback_handler function, allowing unauthenticated users to update the status of arbitrary WooCommerce orders

CPENameOperatorVersion
eq3.8.0

6.6 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

20.5%

Related for WPVDB-ID:E987660E-C872-4C87-B45B-46A273ADFF16