CVE-2023-51503: WordPress WooCommerce Payments Plugin <= 6.6.2 is vulnerable to Insecure Direct Object References (IDOR)
Authorization Bypass Through User-Controlled Key vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo.This issue affects WooPayments – Fully Integrated Solution Built and Supported by Woo: from n/a through 6.9.2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-51503?
CVE-2023-51503 is classified as a medium severity vulnerability due to the potential for unauthorized access.
How do I fix CVE-2023-51503?
To fix CVE-2023-51503, update the WooPayments plugin to version 6.9.3 or later.
What types of systems are affected by CVE-2023-51503?
CVE-2023-51503 affects WooPayments plugin versions from n/a through 6.9.2, integrated with WordPress.
What does CVE-2023-51503 exploit?
CVE-2023-51503 exploits an authorization bypass through user-controlled keys, allowing unauthorized actions.
Is CVE-2023-51503 actively being exploited?
As of now, there is no public indication that CVE-2023-51503 is actively being exploited in the wild.