The WooCommerce EAN Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the refresh_order_ean_data AJAX action in versions up to 6.1.0. This makes it possible for authenticated attackers with contributor-level access and above, to update EAN numbers for orders.
References
Configurations
History
12 Feb 2025, 16:02
Type | Values Removed | Values Added |
---|---|---|
First Time |
Yanco
Yanco woocommerce Ean Payment Gateway |
|
CPE | cpe:2.3:a:yanco:woocommerce_ean_payment_gateway:*:*:*:*:*:wordpress:*:* |
Information
Published : 2023-10-20 07:15
Updated : 2025-02-12 16:02
NVD link : CVE-2023-4947
Mitre link : CVE-2023-4947
CVE.ORG link : CVE-2023-4947
JSON object : View
Products Affected
yanco
- woocommerce_ean_payment_gateway
CWE
CWE-862
Missing Authorization