Mercado Pago payments for WooCommerce, 41b175013b292edd03143070e2e9a0f6ba91a9e0
- CVE, Research URL
- Application
- Published on
- Jan 23, 2023
- Research Description
- Mercado Pago payments for WooCommerce [woocommerce-mercadopago] < 6.7.0 Mercado Pago payments for WooCommerce <= 6.6.0 - Cross-Site Request Forgery The Mercado Pago payments for WooCommerce plugin is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.6.0. This is due to missing or incorrect nonce validation on the 'process_payment' function. This makes it possible for unauthenticated attackers to trick other users or visitors into checking out via a forged request.
- Affected versions
-
max 6.7.0.
- Status
-
vulnerable