Accept Stripe Payments < 2.1.4 - Unauthenticated Product Substitution via IDOR
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 5.3epss 0.2%
exploitation probability
0.2%top 87% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The Accept Stripe Payments WordPress plugin before 2.1.4 does not verify that the product fulfilled when a checkout is completed matches the product the authoritative payment was actually made for, checking only that the amount paid is at least the referenced product's price, allowing unauthenticated attackers who complete a genuine payment to obtain fulfilment for a different, equal- or lower-priced product than the one they paid for.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Affected products
Unknown · Accept Stripe Paymentspublic PoCs found — 1
cve_referencewpscan.com/vulnerability/64c20ce4-d94d-4f09-8d95-9ba232066f62/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.