CVE-2023-7291: Paytium: Mollie payment forms & donations <= 4.3.7 - Missing Authorization in 'create_mollie_account'
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the createmollieaccount function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to set up a mollie account.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-7291?
CVE-2023-7291 has a medium severity rating due to its potential for unauthorized data modification.
How do I fix CVE-2023-7291?
To fix CVE-2023-7291, update the Paytium: Mollie payment forms & donations plugin to version 4.4.0 or later.
Who is affected by CVE-2023-7291?
CVE-2023-7291 affects all versions of the Paytium plugin up to and including 4.3.7 on WordPress.
What could an attacker do with CVE-2023-7291?
An attacker could exploit CVE-2023-7291 to make unauthorized modifications to data within the affected WordPress site.
Is there a patch for CVE-2023-7291?
Yes, a patch is included in the updated version 4.4.0 of the Paytium plugin, which resolves the vulnerability.