plugin

Integrar Getnet Con Woo Vulnerabilities

2 known security issues reported for the Integrar Getnet Con Woo WordPress plugin. Most recent disclosed Jul 12, 2023.

1 high

Running Integrar Getnet Con Woo on your site? Check whether your installed version is affected.

Scan your site free

Getnet Argentina para WooCommerce [integrar-getnet-con-woo] >= 0.0.1 - <= 0.0.4

unknown

[en] The Getnet Argentina para Woocommerce plugin for WordPress is vulnerable to authorization bypass due to missing validation on the 'webhook' function in versions up to, and including, 0.0.4. This makes it possible for unauthenticated attackers to set their payment status to 'APPROVED' without payment.

Affected:
0.0.1 – 0.0.4
Fixed in:
0.0.4
Disclosed:
Jul 12, 2023

CVE-2023-3525 on NVD →

Getnet Argentina para Woocommerce 0.0.1 - 0.0.4 - Authorization Bypass via webhook

high

The Getnet Argentina para Woocommerce plugin for WordPress is vulnerable to authorization bypass due to missing validation on the 'webhook' function in versions up to, and including, 0.0.4. This makes it possible for unauthenticated attackers to set their payment status to 'APPROVED' without payment.

CVSS:
7.5
Affected:
0.0.1 – 0.0.4
Fixed in:
0.0.5
Disclosed:
Jul 7, 2023

CVE-2023-3525 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database