CVE-2023-7289: Paytium: Mollie payment forms & donations <= 4.3.7 - Missing Authorization in 'paytium_sw_save_api_keys'
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized API key update due to a missing capability check on the paytiumswsaveapikeys function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to change plugin API keys.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-7289?
CVE-2023-7289 has been classified as a high severity vulnerability.
How do I fix CVE-2023-7289?
To fix CVE-2023-7289, update the Paytium: Mollie payment forms & donations plugin to version 4.4.0 or higher.
What systems are affected by CVE-2023-7289?
CVE-2023-7289 affects versions of the Paytium plugin for WordPress up to and including 4.3.7.
Who can exploit CVE-2023-7289?
Authenticated attackers can exploit CVE-2023-7289 to unauthorizedly update the API keys.
What is the function involved in CVE-2023-7289?
The vulnerability in CVE-2023-7289 is due to a missing capability check in the paytium_sw_save_api_keys function.