The Stripe for WooCommerce WordPress plugin is missing a capability check on the save() function found in the ~/includes/admin/class-wc-stripe-admin-user-edit.php file that makes it possible for attackers to configure their account to use other site users unique STRIPE identifier and make purchases with their payment accounts. This affects versions 3.0.0 - 3.3.9.
History

Mon, 31 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2021-10-04T17:21:49.430Z

Updated: 2025-03-31T18:11:15.927Z

Reserved: 2021-08-20T00:00:00.000Z

Link: CVE-2021-39347

cve-icon Vulnrichment

Updated: 2024-08-04T02:06:42.468Z

cve-icon NVD

Status : Modified

Published: 2021-10-04T18:15:09.433

Modified: 2024-11-21T06:19:22.160

Link: CVE-2021-39347

cve-icon Redhat

No data.