Security News > 2023 > June > Critical Security Vulnerability Discovered in WooCommerce Stripe Gateway Plugin
![Critical Security Vulnerability Discovered in WooCommerce Stripe Gateway Plugin](/static/build/img/news/critical-security-vulnerability-discovered-in-woocommerce-stripe-gateway-plugin-medium.jpg)
A security flaw has been uncovered in the WooCommerce Stripe Gateway WordPress plugin that could lead to the unauthorized disclosure of sensitive information.
WooCommerce Stripe Gateway allows e-commerce websites to directly accept various payment methods through Stripe's payment processing API. It boasts of over 900,000 active installations.
According to Patch security researcher Rafie Muhammad, the plugin suffers from what's called an unauthenticated Insecure direct object references vulnerability, which allows a bad actor to bypass authorization and access resources.
Specially, the problem stems from the insecure handling of order objects and a lack of adequate access control mechanism in the plugin's 'javascript params' and 'payment fields' functions of the plugin.
"This vulnerability allows any unauthenticated user to view any WooCommnerce order's PII data including email, user's name, and full address," Muhammad said.
The development comes weeks after the WordPress core team released 6.2.1 and 6.2.2 to address five security issues, including an unauthenticated directory traversal vulnerability and an unauthenticated cross-site scripting flaw, three of which were uncovered during a third-party security audit.
News URL
https://thehackernews.com/2023/06/critical-security-vulnerability.html
Related news
- Microsoft Issues Patches for 51 Flaws, Including Critical MSMQ Vulnerability (source)
- ZKTeco Biometric System Found Vulnerable to 24 Critical Security Flaws (source)
- VMware fixes critical vCenter RCE vulnerability, patch now (source)
- Critical RCE Vulnerability Discovered in Ollama AI Infrastructure Tool (source)
- Critical SQLi Vulnerability Found in Fortra FileCatalyst Workflow Application (source)
- GitLab Releases Patch for Critical CI/CD Pipeline Vulnerability and 13 Others (source)
- Juniper Networks Releases Critical Security Update for Routers (source)
- Critical vulnerability in the RADIUS protocol leaves networking equipment open to attack (source)
- Critical Exim Mail Server Vulnerability Exposes Millions to Malicious Attachments (source)
- Critical Exim bug bypasses security filters on 1.5 million mail servers (source)