CVE-2021-39347
Last modified
CVE-2021-39347 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. The Stripe for WooCommerce WordPress plugin is missing a capability check on the save() function found in the ~/includes/admin/class-wc-stripe-admin-user-edit.php file that makes it possible for attackers to configure their account to use other site users unique STRIPE identifier and make purchases with their payment accounts. This affects versions 3.0.0 - 3.3.9.. EPSS estimates a 0.65% chance of exploitation in the next 30 days.
Description
The Stripe for WooCommerce WordPress plugin is missing a capability check on the save() function found in the ~/includes/admin/class-wc-stripe-admin-user-edit.php file that makes it possible for attackers to configure their account to use other site users unique STRIPE identifier and make purchases with their payment accounts. This affects versions 3.0.0 - 3.3.9.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Paymentplugins | Stripe For Woocommerce | >= 3.0.0, <= 3.3.9 |
References
- https://www.wordfence.com/vulnerability-advisories/#CVE-2021-39347Third Party Advisory
- https://www.wordfence.com/vulnerability-advisories/#CVE-2021-39347Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-39347?
How severe is CVE-2021-39347?
How do I fix CVE-2021-39347?
Are you affected by CVE-2021-39347?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
