all InfoSec news
WebToffee Addresses Authentication Bypass Vulnerability in Stripe Payment Plugin for WooCommerce WordPress Plugin
Malware Analysis, News and Indicators - Latest topics malware.news
On June 8, 2023, our Wordfence Threat Intelligence team identified and began the responsible disclosure process for an Authentication Bypass vulnerability in WebToffee’s Stripe Payment Plugin for WooCommerce plugin, which is actively installed on more than 10,000 WordPress websites. This vulnerability makes it possible for an attacker to gain access to the accounts of users who have orders. These users are typically customers but can include other high-level users when the right conditions are met.
Wordfence Premium, Wordfence …
addresses authentication authentication bypass bypass bypass vulnerability disclosure intelligence june payment plugin process responsible responsible disclosure stripe team threat threat intelligence vulnerability websites woocommerce wordfence wordpress wordpress plugin