CVE · Medium

CVE-2023-44999 — WooCommerce Stripe Payment Gateway [woocommerce-gateway-stripe] < 7.6.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-44999 WooCommerce Stripe Payment Gateway [woocommerce-gateway-stripe] < 7.6.1 Cross-Site Request Forgery (CSRF) Medium 5.4 < 7.6.1 7.6.1 2023-10-17

CVE-2023-44999

The WooCommerce Stripe Payment Gateway plugin before version 7.6.1 contains a cross-site request forgery vulnerability that could enable attackers to trick authenticated users with elevated privileges into performing actions without their knowledge. A malicious actor could exploit this flaw to execute unauthorized operations on behalf of compromised administrators or other high-level users. The issue has been resolved in version 7.6.1 and users should upgrade immediately.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.