cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forwoocommerce-payments woocommerce-payments

Direction: descending
Jun 07, 2024

WooPayments: Integrated WooCommerce Payments # 1ad997f7b769fb925cf6bedd63b85b914e27cfc8

Date
Mar 23, 2023
Research Description
WooPayments: Integrated WooCommerce Payments [woocommerce-payments] < 5.6.2 WooCommerce Payments 4.8.0 - 5.6.1 Authentication Bypass and Privilege Escalation The WooCommerce Payments plugin is vulnerable to authentication bypass via the determine_current_user_for_platform_checkout function. This allows unauthenticated attackers to impersonate arbitrary users and perform some actions as the impersonated user, which can lead to site takeover.
Affected versions
Min -, max -.
Status
vulnerable

WooPayments: Integrated WooCommerce Payments # CVE-2023-28121

CVE, Research URL

CVE-2023-28121

Date
Apr 13, 2023
Research Description
An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an elevated user, like administrator. This allows a remote, unauthenticated attacker to gain admin access on a site that has the affected version of the plugin activated.
Affected versions
Min -, max -.
Status
vulnerable

WooPayments: Integrated WooCommerce Payments # CVE-2023-35915

CVE, Research URL

CVE-2023-35915

Date
Dec 20, 2023
Research Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo.This issue affects WooPayments – Fully Integrated Solution Built and Supported by Woo: from n/a through 5.9.0.
Affected versions
Min -, max -.
Status
vulnerable

WooPayments: Integrated WooCommerce Payments # CVE-2023-35916

CVE, Research URL

CVE-2023-35916

Date
Dec 20, 2023
Research Description
Authorization Bypass Through User-Controlled Key vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo.This issue affects WooPayments – Fully Integrated Solution Built and Supported by Woo: from n/a through 5.9.0.
Affected versions
Min -, max -.
Status
vulnerable

WooPayments: Integrated WooCommerce Payments # CVE-2023-51503

CVE, Research URL

CVE-2023-51503

Date
Dec 31, 2023
Research Description
Authorization Bypass Through User-Controlled Key vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo.This issue affects WooPayments – Fully Integrated Solution Built and Supported by Woo: from n/a through 6.9.2.
Affected versions
Min -, max -.
Status
vulnerable

WooPayments: Integrated WooCommerce Payments # CVE-2023-49828

CVE, Research URL

CVE-2023-49828

Date
Dec 14, 2023
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo allows Stored XSS.This issue affects WooPayments – Fully Integrated Solution Built and Supported by Woo: from n/a through 6.4.2.
Affected versions
Min -, max -.
Status
vulnerable