CVE-2023-44999: WordPress WooCommerce Stripe Gateway plugin <= 7.6.0 - Cross Site Request Forgery (CSRF) vulnerability
Published Mar 27, 2024
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue affects WooCommerce Stripe Payment Gateway: from n/a through 7.6.0.
Affected Software
3 affected components
WooCommerce WooCommerce Stripe Payment Gateway<=7.6.0
WordPress WooCommerce Stripe Gateway<=7.6.0
WooCommerce Stripe Payment Gateway Wordpress<=7.6.0
Remediation
Information
Update to 7.6.1 or a higher version.
Event History
Mar 27, 2024
CVE Published
via MITRE·01:27 PM
Data Sourced
via MITRE·01:27 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-44999?
CVE-2023-44999 is classified as a moderate severity Cross-Site Request Forgery (CSRF) vulnerability.
2
How do I fix CVE-2023-44999?
To fix CVE-2023-44999, update the WooCommerce Stripe Payment Gateway to version 7.6.1 or later.
3
Which versions of WooCommerce Stripe Payment Gateway are affected by CVE-2023-44999?
CVE-2023-44999 affects versions of WooCommerce Stripe Payment Gateway up to and including 7.6.0.
4
What type of attack does CVE-2023-44999 facilitate?
CVE-2023-44999 facilitates Cross-Site Request Forgery (CSRF) attacks.
5
Who is affected by CVE-2023-44999?
Users of the WooCommerce Stripe Payment Gateway from version n/a to 7.6.0 are affected by CVE-2023-44999.