CVE-2023-3525
PoC —CVSS 3.1
7.5 high
EPSS
<1%p54
Published
()
Modified
Description
The Getnet Argentina para Woocommerce plugin for WordPress is vulnerable to authorization bypass due to missing validation on the 'webhook' function in versions up to, and including, 0.0.4. This makes it possible for unauthenticated attackers to set their payment status to 'APPROVED' without payment.
- Vendors
- getnet argentina para woocommerce project
- Products
- getnet argentina para woocommerce
- Ecosystems
- WordPress, E-commerce
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.