ZeroHour

CVE-2023-3525

PoC
CVSS 3.1
7.5 high
EPSS
<1%p54
Published
()
Modified
Description

The Getnet Argentina para Woocommerce plugin for WordPress is vulnerable to authorization bypass due to missing validation on the 'webhook' function in versions up to, and including, 0.0.4. This makes it possible for unauthenticated attackers to set their payment status to 'APPROVED' without payment.

Vendors
getnet argentina para woocommerce project
Products
getnet argentina para woocommerce
Ecosystems
WordPress, E-commerce
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.