PT-2023-31784 · Unknown+1 · Woocommerce+2
Francesco Carlucci
·
Published
2023-10-21
·
Updated
2023-10-28
·
CVE-2023-5132
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Soisy Pagamento Rateale plugin for WordPress versions up to, and including, 6.0.1
Description
The issue allows unauthorized access to data due to a missing capability check on the
parseRemoteRequest function. This makes it possible for unauthenticated attackers with knowledge of an existing WooCommerce Order ID to expose sensitive WooCommerce order information, such as Name, Address, Email Address, and other order metadata.Recommendations
For Soisy Pagamento Rateale plugin for WordPress versions up to, and including, 6.0.1, update to a version higher than 6.0.1 to resolve the issue. As a temporary workaround, consider restricting access to the
parseRemoteRequest function to prevent unauthorized data exposure.Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Soisy Pagamento Rateale
Woocommerce
Wordpress