CVE-2023-7294: Paytium: Mollie payment forms & donations <= 4.3.7 - Missing Authorization in 'create_mollie_profile'
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the createmollieprofile function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to create a mollie payment profile.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-7294?
CVE-2023-7294 has been rated as a high severity vulnerability due to its potential for unauthorized data modification.
How can I fix CVE-2023-7294?
To fix CVE-2023-7294, update the Paytium plugin to version 4.4.0 or later, where the vulnerability is addressed.
Who is affected by CVE-2023-7294?
CVE-2023-7294 affects all WordPress sites using versions of the Paytium plugin up to and including 4.3.7.
What type of attack does CVE-2023-7294 enable?
CVE-2023-7294 allows authenticated attackers to perform unauthorized data modifications due to a missing capability check.
Is there a patch available for CVE-2023-7294?
Yes, a patch for CVE-2023-7294 is available in Paytium plugin version 4.4.0 and later.