CVE · High

CVE-2023-51502 — WooCommerce Stripe Payment Gateway [woocommerce-gateway-stripe] < 7.6.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-51502 WooCommerce Stripe Payment Gateway [woocommerce-gateway-stripe] < 7.6.2 Authorization Bypass Through User-Controlled Key High 7.5 < 7.6.2 7.6.2 2023-12-27

CVE-2023-51502

The WooCommerce Stripe Payment Gateway plugin versions prior to 7.6.2 contain an insecure direct object reference vulnerability that permits attackers to circumvent authentication and authorization controls. This flaw enables unauthorized actors to gain access to restricted files, folders, and database information. The vulnerability was discovered by Rafie Muhammad and has been patched in version 7.6.2 and later releases.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.