PII Exposed: Unauthenticated IDOR in WooCommerce Stripe Plugin

A critical security vulnerability has been discovered in the popular WooCommerce Stripe Gateway plugin, which could expose users’ personally identifiable information (PII).

This vulnerability affects versions 7.4.0 and below of the Unauthenticated Insecure Direct Object Reference (IDOR) plugin, which boasts over 900,000 active installations.

“This plugin is a WordPress plugin that allows you to accept payments directly on your web and mobile stores,” Patchstack security researcher Rafie Muhammad said in an advisory published Tuesday.

“This plugin allows customers to remain in-store during checkout instead of being redirected to an externally hosted checkout page.”

Muhammad added that the flaw could allow unauthorized users to access user information associated with WooCommerce orders.

“This vulnerability allows unauthenticated users to view PII data for WooCommnerce orders, including email, username and full address.”

For more information on WordPress plugin vulnerabilities, see Essential Addons Plugin Flaw Exsess One Million WordPress Websites.

From a technical perspective, this vulnerability is due to insufficient validation of order ownership and can be exploited by manipulating query parameters. This flaw allows an attacker to bypass authentication controls and extract her PII data.

In the Patchstack advisory, Muhammad said a security firm discovered the flaw and disclosed it to WooCommerce on April 17, 2023.

The plugin vendor then released a patch on May 30th to address this vulnerability. To mitigate the risk, you should install WooCommerce Stripe Gateway version 7.4.1 or a later version now.

“If you are a WooCommerce Stripe Gateway user, please update your plugin to at least version 7.4.1,” Muhammad said.

Despite the patch, security researchers are urging website owners and developers using the WooCommerce Stripe Gateway plugin to stay vigilant and check order keys and ownership to ensure access to order objects. I warned you to always check your controls.

The WooCommerce patch comes months after the company behind the popular WordPress plugin Elementor updated its product to fix a critical vulnerability that could be exploited to change the look of your website. provided later.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *