Getnet Argentina para WooCommerce [integrar-getnet-con-woo] >= 0.0.1 - <= 0.0.4
unknown
[en] The Getnet Argentina para Woocommerce plugin for WordPress is vulnerable to authorization bypass due to missing validation on the 'webhook' function in versions up to, and including, 0.0.4. This makes it possible for unauthenticated attackers to set their payment status to 'APPROVED' without payment.
- Affected:
- 0.0.1 – 0.0.4
- Fixed in:
- 0.0.4
- Disclosed:
- Jul 12, 2023
CVE-2023-3525 on NVD →
Getnet Argentina para Woocommerce 0.0.1 - 0.0.4 - Authorization Bypass via webhook
high
The Getnet Argentina para Woocommerce plugin for WordPress is vulnerable to authorization bypass due to missing validation on the 'webhook' function in versions up to, and including, 0.0.4. This makes it possible for unauthenticated attackers to set their payment status to 'APPROVED' without payment.
- CVSS:
- 7.5
- Affected:
- 0.0.1 – 0.0.4
- Fixed in:
- 0.0.5
- Disclosed:
- Jul 7, 2023
CVE-2023-3525 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database