CVE-2023-37871: WordPress WooCommerce GoCardless Gateway Plugin <= 2.5.6 is vulnerable to Insecure Direct Object References (IDOR)
Published Dec 20, 2023
·Updated
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce GoCardless.This issue affects GoCardless: from n/a through 2.5.6.
Affected Software
1 affected component
Automattic Woocommerce Gocardless Wordpress<2.5.7
Remediation
Information
Update to 2.5.7 or a higher version.
Event History
Dec 20, 2023
CVE Published
via MITRE·01:57 PM
Data Sourced
via MITRE·01:57 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-37871?
CVE-2023-37871 has been classified as a high-severity vulnerability due to its potential for unauthorized access.
2
How do I fix CVE-2023-37871?
To mitigate CVE-2023-37871, update WooCommerce GoCardless to version 2.5.7 or higher.
3
What type of vulnerability is CVE-2023-37871?
CVE-2023-37871 is an Authorization Bypass Through User-Controlled Key vulnerability.
4
Which versions of WooCommerce GoCardless are affected by CVE-2023-37871?
CVE-2023-37871 affects WooCommerce GoCardless versions from n/a through 2.5.6.
5
What is the impact of CVE-2023-37871 on website security?
CVE-2023-37871 could allow attackers to bypass authorization controls, leading to unauthorized access to sensitive data.