HomeSecurityWooCommerce Stripe Gateway plugin - WordPress: Vulnerability exposes user order details

WooCommerce Stripe Gateway plugin – WordPress: Vulnerability exposes user order details

A serious vulnerability has been identified in the WooCommerce Stripe Gateway plugin for WordPress, which allows unauthenticated users to view the details of an order submitted through the plugin.

WordPress plugins

WooCommerce Stripe Payment is a payment gateway for WordPress e-commerce. The plugin has over 900,000 active installations. It allows sites to accept payment methods such as Visa, MasterCard, American Express, Apple Pay, and Google Pay through Stripe's payment processing API.

See also: WordPress: Automatic update to fix vulnerability in Jetpack plugin

Security analysts at Patchstack discovered that the plugin is vulnerable to the CVE-2023-34000 vulnerability . This is an “ insecure direct object reference (IDOR) ” vulnerability, which could expose sensitive details to attackers.

The vulnerability could allow unauthenticated users to view data from the checkout page. This page also contains personal information, such as email addresses, shipping , and the user's full name.

This data can help attackers carry out additional attacks, such as compromise attempts account and credential theft through targeted phishing emails.

See also: Microsoft Patch Tuesday June 2023: Fixes 78 vulnerabilities

The vulnerability affects all versions of WooCommerce Stripe Gateway prior to 7.4.1. Users are urged to upgrade the plugin to version 7.4.1 to stay safe.

Patchstack discovered and reported the CVE-2023-34000 vulnerability to the plugin vendor on April 17, 2023. Update 7.4.1 was released on May 30, 2023.

According to WordPress.org statistics, more than half of the plugin's active installations are currently using a vulnerable version.

WooCommerce Stripe Gateway plugin

Applying the update is considered necessary considering that cybercriminals often target vulnerable plugins. In the past few months alone, attacks have been carried out through vulnerabilities in Elementor Pro, Advanced Custom Fields, Essential Addons for Elementor, Beautiful Cookie Consent Banner, and many others.

See also: WordPress: Hackers target 1.5 million websites

WordPress site administrators should ensure that their plugins are updated. It is also recommended to disable those that are not needed/used and monitor sites for suspicious activity such as file modifications , changing settings, or creating new administrator accounts.

Vulnerabilities pose a significant risk to your business, but by following best practices and implementing a prevention-based security strategy, you can minimize the impact of potential attacks and protect your organization from damage

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS