CVE-2023-3525
The Getnet Argentina para Woocommerce plugin for WordPress is vulnerable to authorization bypass due to missing validation on the 'webhook' function in versions up to, and including, 0.0.4.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.77%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Getnet Argentina para Woocommerce plugin for WordPress is vulnerable to authorization bypass due to missing validation on the 'webhook' function in versions up to, and including, 0.0.4. This makes it possible for unauthenticated attackers to set their payment status to 'APPROVED' without payment.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.77% probability · 54th percentile
- CISA KEV
- Not listed
- Affected
- getnet argentina para woocommerce project/getnet argentina para woocommerce
- Source
- security@wordfence.com
References
- https://www.wordfence.com/threat-intel/vulnerabilities/id/245e9117-ca63-458e-a094-60a759f5ec19?source=cveThird Party Advisory
- https://www.youtube.com/watch?v=xTyWqh93AM0Exploit
- https://www.wordfence.com/threat-intel/vulnerabilities/id/245e9117-ca63-458e-a094-60a759f5ec19?source=cveThird Party Advisory
- https://www.youtube.com/watch?v=xTyWqh93AM0Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.