Описание
The GetPaid WordPress plugin before 2.8.55 does not verify the authenticity of incoming Worldpay payment notifications, allowing unauthenticated attackers to forge a notification that marks a pending invoice as paid without any payment being made.
EPSS
Процентиль: 3%
0.00125
Низкий
5.9 Medium
CVSS3
Дефекты
CWE-345
Связанные уязвимости
CVSS3: 5.9
github
12 дней назад
The GetPaid WordPress plugin before 2.8.55 does not verify the authenticity of incoming Worldpay payment notifications, allowing unauthenticated attackers to forge a notification that marks a pending invoice as paid without any payment being made.
EPSS
Процентиль: 3%
0.00125
Низкий
5.9 Medium
CVSS3
Дефекты
CWE-345