CVE-2023-7293: Paytium: Mollie payment forms & donations <= 4.3.7 - Missing Authorization in 'check_mollie_account_details'
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the checkmollieaccountdetails function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to verify the existence of a mollie account.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-7293?
The severity of CVE-2023-7293 is considered critical due to the potential for unauthorized data access.
How do I fix CVE-2023-7293?
To fix CVE-2023-7293, update the Paytium: Mollie payment forms & donations plugin to version 4.4.0 or later.
Who is affected by CVE-2023-7293?
CVE-2023-7293 affects users of versions up to and including 4.3.7 of the Paytium plugin for WordPress.
What does CVE-2023-7293 exploit?
CVE-2023-7293 exploits a missing capability check in the check_mollie_account_details function.
Can authenticated attackers exploit CVE-2023-7293?
Yes, authenticated attackers can exploit CVE-2023-7293 to gain unauthorized access to sensitive data.