Vulnerabilities (CVE)

Filtered by vendor Getnet Argentina Para Woocommerce Project Subscribe
Filtered by product Getnet Argentina Para Woocommerce
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-3525 1 Getnet Argentina Para Woocommerce Project 1 Getnet Argentina Para Woocommerce 2024-02-04 N/A 7.5 HIGH
The Getnet Argentina para Woocommerce plugin for WordPress is vulnerable to authorization bypass due to missing validation on the 'webhook' function in versions up to, and including, 0.0.4. This makes it possible for unauthenticated attackers to set their payment status to 'APPROVED' without payment.