Stripe Payments For WooCommerce by Checkout <= 1.9.1 - Unauthenticated Insecure Direct Object Reference
medium
The Stripe Payments For WooCommerce by Checkout Plugins plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.9.1 via the verify_intent() due to missing validation on the 'order' user controlled key. This makes it possible for unauthenticated attackers to access...
- CVSS:
- 5.3
- Affected:
- up to 1.9.1
- Fixed in:
- 1.9.2
- Disclosed:
- Aug 16, 2024
CVE-2024-43315 on NVD →
Stripe Payments For WooCommerce by Checkout <= 1.9.1 - Cross-Site Request Forgery
medium
The Stripe Payments For WooCommerce by Checkout plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.9.1. This is due to missing or incorrect nonce validation on the verify_intent() function. This makes it possible for unauthenticated attackers to confirm orders via a for...
- CVSS:
- 4.3
- Affected:
- up to 1.9.1
- Fixed in:
- 1.9.2
- Disclosed:
- Aug 16, 2024
CVE-2024-43316 on NVD →
Stripe Payments For WooCommerce by Checkout Plugins <= 1.4.10 - Cross-Site Request Forgery
medium
The Stripe Payments For WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.10. This is due to missing or incorrect nonce validation on the cpsw_express_checkout_option_updates function. This makes it possible for unauthenticated attackers to invoke that fu...
- CVSS:
- 5.4
- Affected:
- up to 1.4.10
- Fixed in:
- 1.4.11
- Disclosed:
- Jan 23, 2023
CVE-2023-23865 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database