QID 730827

Date Published: 2023-06-29

QID 730827: WordPress Plugin WooCommerce Stripe Gateway Insecure Direct Object References (IDOR) Vulnerability

WooCommerce Stripe Gateway WordPress plugin which allows you to accept payments directly on a store for web and mobile. With the plugin, customers can stay on the store during checkout instead of being redirected to an externally hosted checkout page.

WooCommerce Stripe Payment Gateway plugin prior to 7.4.1 versions is vulnerable to unauthenticated IDOR vulnerability leading to PII Disclosure

Affected versions:
WooCommerce Stripe Payment Gateway versions prior to 7.4.1

QID Detection Logic:
This unauthenticated detection depends on the BlindElephant engine to detect the vulnerable version of the WooCommerce Stripe Payment Gateway WordPress plugin.

Successful exploitation of this vulnerability may allow an unauthenticated attacker to perform IDOR vulnerability leading to PII Disclosure.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to upgrade to WooCommerce Stripe Payment Gateway 7.4.1 or later version to remediate this vulnerability.
    Vendor References

    CVEs related to QID 730827

    Software Advisories
    Advisory ID Software Component Link
    WooCommerce Stripe Payment Gateway Release Notes URL Logo wordpress.org/plugins/woocommerce-gateway-stripe/#developers