CVE-2023-51502: WordPress WooCommerce Stripe Payment Gateway Plugin <= 7.6.1 is vulnerable to Insecure Direct Object References (IDOR)
Published Jan 5, 2024
·Updated
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue affects WooCommerce Stripe Payment Gateway: from n/a through 7.6.1.
Affected Software
1 affected component
Automattic Woocommerce Stripe Wordpress<=7.6.1
Remediation
Information
Update to 7.6.2 or a higher version.
Event History
Jan 5, 2024
CVE Published
via MITRE·07:56 AM
Data Sourced
via MITRE·07:56 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-51502?
CVE-2023-51502 is classified as a high severity vulnerability due to its potential for unauthorized access.
2
How do I fix CVE-2023-51502?
To fix CVE-2023-51502, update the WooCommerce Stripe Payment Gateway plugin to version 7.6.2 or later.
3
What systems are affected by CVE-2023-51502?
CVE-2023-51502 affects WooCommerce Stripe Payment Gateway versions up to and including 7.6.1.
4
What type of vulnerability is CVE-2023-51502?
CVE-2023-51502 is an authorization bypass vulnerability that allows user-controlled key manipulation.
5
Can CVE-2023-51502 lead to data exposure?
Yes, CVE-2023-51502 can lead to unauthorized access to sensitive user data due to improper authorization checks.