CVE-2023-7287: Paytium: Mollie payment forms & donations <= 4.3.7 - Missing Authorization in 'pt_cancel_subscription'
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized subscription cancellation due to a missing capability check on the ptcancelsubscription function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to cancel a subscription to the plugin.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-7287?
CVE-2023-7287 has a medium severity due to the potential for unauthorized cancellation of subscriptions.
How do I fix CVE-2023-7287?
To fix CVE-2023-7287, update the Paytium: Mollie payment forms & donations plugin to version 4.4.0 or later.
Who is affected by CVE-2023-7287?
CVE-2023-7287 affects users of Paytium: Mollie payment forms & donations plugin for WordPress versions up to and including 4.3.7.
What functionality is compromised in CVE-2023-7287?
CVE-2023-7287 compromises the subscription cancellation functionality due to a missing capability check.
Is authentication required to exploit CVE-2023-7287?
Yes, an authenticated user is required to exploit CVE-2023-7287 and cancel subscriptions without proper authorization.