🔐 CVE Alert

CVE-2023-3525

HIGH 7.5
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

The Getnet Argentina para Woocommerce plugin for WordPress is vulnerable to authorization bypass due to missing validation on the 'webhook' function in versions up to, and including, 0.0.4. This makes it possible for unauthenticated attackers to set their payment status to 'APPROVED' without payment.

Vendor wanderlustcodes
Product getnet argentina para woocommerce
Published Jul 12, 2023
Last Updated Feb 5, 2025
Stay Ahead of the Next One

Get instant alerts for wanderlustcodes getnet argentina para woocommerce

Be the first to know when new high vulnerabilities affecting wanderlustcodes getnet argentina para woocommerce are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

wanderlustcodes / Getnet Argentina para Woocommerce
0.0.1 ≤ 0.0.4

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/245e9117-ca63-458e-a094-60a759f5ec19?source=cve youtube.com: https://www.youtube.com/watch?v=xTyWqh93AM0

Credits

Kijam López