CVE-2023-4040
Webtoffee Stripe Payment Plugin For Woocommerce ≤ 3.8.0
Raw vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NSummary
CVE-2023-4040 is a medium-severity an unspecified weakness vulnerability in Webtoffee Stripe Payment Plugin For Woocommerce. Its CVSS base score is 5.3 (Medium).
Operationally, ranked at the 32th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2023-53932
Vulnerability Data
The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the eh_callback_handler function in versions up to, and including, 3.7.9. This makes it possible for unauthenticated attackers…
more
to modify the order status of arbitrary WooCommerce orders.
- CWE(s)
Related Threats
CVEs Like This One
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.