cleantalk
Vulnerabilities and Security Researches

WooCommerce Stripe Payment Gateway, a1aef5d00a17caff6e3316a98fe922109481691a

Published on
Oct 17, 2023
Research Description
WooCommerce Stripe Payment Gateway [woocommerce-gateway-stripe] < 7.6.1 Stripe Gateway <= 7.6.0 - Cross-Site Request Forgery The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to 7.6.1 (exclusive). This is due to missing or incorrect nonce validation on the maybe_handle_redirect function. This makes it possible for unauthenticated attackers to change the stripe connection via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 7.6.1.
Status
vulnerable