CVE Vulnerabilities

CVE-2023-3162

Authentication Bypass Using an Alternate Path or Channel

Published: Aug 31, 2023 | Modified: Apr 08, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.7.7. This is due to insufficient verification on the user being supplied during a Stripe checkout through the plugin. This allows unauthenticated attackers to log in as users who have orders, who are typically customers.

Weakness

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Affected Software

NameVendorStart VersionEnd Version
Stripe_payment_plugin_for_woocommerceWebtoffee*3.7.7 (including)

Potential Mitigations

References