PT-2023-19312 · Unknown · Security Plugin+1
Highmstegmeyer
·
Published
2023-02-03
·
Updated
2023-02-15
·
CVE-2023-23941
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
SwagPayPal versions prior to 5.4.4
Description
The issue affects JavaScript-based PayPal checkout methods, including PayPal Plus, Smart Payment Buttons, SEPA, Pay Later, Venmo, and Credit card. When these methods are used, the amount and item list sent to PayPal may not match the ones in the created order.
Recommendations
For versions prior to 5.4.4, update to version 5.4.4 to resolve the issue.
As a temporary workaround, consider disabling the JavaScript-based PayPal checkout methods, such as PayPal Plus, Smart Payment Buttons, SEPA, Pay Later, Venmo, and Credit card, until the update is applied.
Alternatively, use the Security Plugin in version 1.0.21 or later as a workaround.
Exploit
Fix
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Security Plugin
Swagpaypal