Описание
The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.2 does not verify that a payment-confirmation request originates from the owner of the targeted order, nor that any payment actually occurred, allowing unauthenticated attackers to mark arbitrary orders as confirmed and, in a non-default configuration, paid.
EPSS
Процентиль: 13%
0.00221
Низкий
5.9 Medium
CVSS3
Дефекты
CWE-287
Связанные уязвимости
CVSS3: 5.9
github
5 дней назад
The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.2 does not verify that a payment-confirmation request originates from the owner of the targeted order, nor that any payment actually occurred, allowing unauthenticated attackers to mark arbitrary orders as confirmed and, in a non-default configuration, paid.
EPSS
Процентиль: 13%
0.00221
Низкий
5.9 Medium
CVSS3
Дефекты
CWE-287