WordPress Plugin Vulnerabilities

Stripe Payment < 3.8.0 - Unauthenticated WC Order Status Update

Description

The plugin does not have authorisation in its eh_callback_handler function, allowing unauthenticated users to update the status of arbitrary WooCommerce orders

Affects Plugins

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Francesco Carlucci
Verified
No

Timeline

Publicly Published
2023-08-17 (about 2 years ago)
Added
2023-08-18 (about 2 years ago)
Last Updated
2023-08-18 (about 2 years ago)

Other