"Hundreds of Thousands of eCommerce Sites Impacted by Critical Plugin Vulnerability"

Security researchers at Patchstack discovered that hundreds of thousands of ecommerce websites could be exposed to attacks due to a critical vulnerability in the WooCommerce Stripe Payment Gateway plugin.  Tracked as CVE-2023-34000, the issue is described as an unauthenticated insecure direct object reference (IDOR) bug leading to information disclosure.  The researchers noted that specifically, the flaw allows an unauthenticated attacker to view any information that a user provides when placing an order, including name, address, and email address.  The security defect exists because the "javascript_params" and "payment_fields" functions lack proper access control and handle data in an insecure manner.  The researchers stated that due to the lack of order ownership checks, an attacker can exploit the bugs to view order information in the site's page source or in the front end.  The issue was resolved on May 30 with the release of WooCommerce Stripe Payment Gateway version 7.4.1.  According to the official WordPress web store, the plugin has more than 900,000 active installations, and hundreds of thousands of them could be vulnerable to attacks based on available version use data. 

 

SecurityWeek reports: "Hundreds of Thousands of eCommerce Sites Impacted by Critical Plugin Vulnerability"

Submitted by Anonymous on