CVE-2023-35049: WordPress WooCommerce Stripe Payment Gateway plugin <= 7.4.0 - Unauthenticated Broken Access Control vulnerability
Published Jun 19, 2024
·Updated
Missing Authorization vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue affects WooCommerce Stripe Payment Gateway: from n/a through 7.4.0.
Affected Software
2 affected components
WooCommerce WooCommerce Stripe Payment Gateway<=7.4.0
WooCommerce Stripe Payment Gateway Wordpress<7.4.1
Remediation
Information
Update to 7.4.1 or a higher version.
Event History
Jun 19, 2024
CVE Published
via MITRE·12:26 PM
Data Sourced
via MITRE·12:26 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-35049?
CVE-2023-35049 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2023-35049?
To fix CVE-2023-35049, update the WooCommerce Stripe Payment Gateway plugin to version 7.4.1 or higher.
3
What type of vulnerability is CVE-2023-35049?
CVE-2023-35049 is a Missing Authorization vulnerability.
4
Which versions of the WooCommerce Stripe Payment Gateway are affected by CVE-2023-35049?
CVE-2023-35049 affects versions up to and including 7.4.0 of the WooCommerce Stripe Payment Gateway.
5
What components are impacted by CVE-2023-35049?
CVE-2023-35049 impacts the WooCommerce Stripe Payment Gateway component.