VendorsWebToffeestripe_payment_plugin_for_woocommerceall versions
Vulnerabilities

WebToffee Stripe Payment Plugin for WooCommerce

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2024-0705
Stripe Payment Plugin for WooCommerce <= 3.7.9 - Unauthenticated SQL Injection
Published 2024-01-19 · Modified
9.8EPSS 0.026
CVE-2023-3162
Stripe Payment Plugin for WooCommerce <= 3.7.7 - Authentication Bypass
Published 2023-08-31 · Modified
9.8EPSS 0.012
CVE-2023-4040
The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the eh_callback_handler function in versions up to, and including, 3.7.9. This makes it possible for unauthenticated attackers to modify the order status of arbitrary WooCommerce orders.
Published 2023-08-18 · Modified
5.3EPSS 0.005