WooCommerce Payments <= 4.5.0 - Payment Bypass

2022-08-09 00:00
Anonymous

Strategic Overview

Status
Patched in 3.9.4
Affected Version3.9.0 – 4.5.0 · 7 branches
CVSS5.3Medium
CVEN/A
View all WooPayments: Integrated WooCommerce Payments vulnerabilities

Vulnerability Overview

The WooCommerce Payments plugin for WordPress is vulnerable to payment bypass in versions up to, and including, 4.5.0. This is due to insufficient controls on checkout payment intent. This makes it possible for unauthenticated users to complete purchases without paying for them.

Technical Analysis

REMEDIATION: Update to one of the following versions, or a newer patched version: 3.9.4, 4.0.3, 4.1.1, 4.2.2, 4.3.1, 4.4.1, 4.5.1 --- IDENTIFIER: CWE-233 (Improper Handling of Parameters) The product does not properly handle when the expected number of parameters, fields, or arguments is not provided in input, or if those parameters are undefined.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C