WooCommerce Stripe Payment Gateway CSRF Vulnerability Affects Users
CVE-2023-44999
5.4MEDIUM
Key Information:
- Vendor
- WordPress
- Vendor
- CVE Published:
- 27 March 2024
Summary
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WooCommerce Stripe Payment Gateway, which may allow unauthorized actions to be executed on behalf of users without their consent. This issue potentially exposes users to significant risks, as an attacker could exploit this vulnerability to invoke unwanted transactions or modify user settings. Affected users of the WooCommerce Stripe Payment Gateway, particularly those using versions up to 7.6.0, should take immediate steps to mitigate the potential impacts of this vulnerability.
Affected Version(s)
WooCommerce Stripe Payment Gateway <= 7.6.0
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Rafie Muhammad (Patchstack)