CVE-2023-7290: Paytium: Mollie payment forms & donations <= 4.3.7 - Missing Authorization in 'check_for_verified_profiles'
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the checkforverifiedprofiles function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to check profile statuses.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-7290?
CVE-2023-7290 is considered a medium severity vulnerability due to the potential for unauthorized data access.
How do I fix CVE-2023-7290?
To fix CVE-2023-7290, update the Paytium: Mollie payment forms & donations plugin to version 4.4.0 or later.
Who is affected by CVE-2023-7290?
CVE-2023-7290 affects users of the Paytium: Mollie payment forms & donations plugin for WordPress versions up to 4.3.7.
What causes CVE-2023-7290?
CVE-2023-7290 is caused by a missing capability check in the check_for_verified_profiles function, allowing unauthorized access.
What kind of attacks can CVE-2023-7290 enable?
CVE-2023-7290 can enable authenticated attackers to gain unauthorized access to sensitive data.