Skip to content
August 18, 2025

Free Websites, share News and Posts publicly

Primary Menu
  • Registration free websites/as writer
  • Login
Live
  • Home
  • [New post] WooCommerce Stripe Gateway Plugin Patches Security Vulnerability in 7.4.1
  • news

[New post] WooCommerce Stripe Gateway Plugin Patches Security Vulnerability in 7.4.1

alisa June 14, 2023 2 min read
Site logo image Sarah Gooding posted: ” Patchstack is reporting an Insecure Direct Object References (IDOR) vulnerability in WooCommerce Stripe Gateway, the most popular WooCommerce Stripe payment plugin with more than 900,000 active users. It was discovered by Patchstack researcher Rafie Muha” WP Tavern

WooCommerce Stripe Gateway Plugin Patches Security Vulnerability in 7.4.1

0bce5db7a60aebfe02859e1f166195737a6a823d6aaa45dfaccc668744d804d0?s=96&d=retro&r=R

Sarah Gooding

Jun 14

Patchstack is reporting an Insecure Direct Object References (IDOR) vulnerability in WooCommerce Stripe Gateway, the most popular WooCommerce Stripe payment plugin with more than 900,000 active users. It was discovered by Patchstack researcher Rafie Muhammad on April 17, 2023, and patched by WooCommerce on May 30, 2023, in version 7.4.1.

The security advisory describes the vulnerability as follows:

This vulnerability allows any unauthenticated user to view any WooCommnerce order’s PII data including email, user’s name, and full address. The described vulnerability was fixed in version 7.4.1 with some backported fixed version and assigned CVE-2023-34000.

It was assigned a high severity CVSS 3.1 score of 7.5 and added to the Patchstack database on June 13.

The vulnerability affects versions 7.4.0 and below. Although the patch from WooCommerce has been available for two weeks, more than 55% of the plugin’s user base is running on versions older than 7.4 and it’s not clear how many 7.4.x users are on the latest version.

Screen Shot 2023 06 14 at 1.13.47 PM

The WooCommerce Stripe Gateway plugin’s changelog for version 7.4.1 includes two short notes and doesn’t elaborate on the severity of the security update:

  • Fix – Add Order Key Validation.
  • Fix – Add sanitization and escaping some outputs.

Patchstack’s security advisory includes more technical details about underlying vulnerabilities fixed in this update. It is not yet known to have been exploited but store owners are encouraged to update to the latest 7.4.1 version as soon as possible.

Comment

Unsubscribe to no longer receive posts from WP Tavern.
Change your email settings at manage subscriptions.

Trouble clicking? Copy and paste this URL into your browser:
https://wptavern.com/woocommerce-stripe-gateway-plugin-patches-security-vulnerability-in-7-4-1

WordPress.com and Jetpack Logos

Get the Jetpack app to use Reader anywhere, anytime

Follow your favorite sites, save posts to read later, and get real-time notifications for likes and comments.

Download Jetpack on Google Play Download Jetpack from the App Store
WordPress.com on Twitter WordPress.com on Facebook WordPress.com on Instagram WordPress.com on YouTube
WordPress.com Logo and Wordmark title=

Learn how to build your website with our video tutorials on YouTube.

Automattic, Inc. – 60 29th St. #343, San Francisco, CA 94110  

t.gif?has featured image=0& ui=8ba62ef4a9e9a49d3fe3da3d5a99ce4d& ut=anon&email domain=gmail.com&blog id=9006382&post id=145864&date sent=2023 06 14&email id=971b4eda1ee7ee4cf037a0960f3cbe48&email name=new post&template=new post& en=wpcom email open&browser type=php agent& aua=wpcom tracks client v0b.gif?blog=9006382&post=145864&subd=wptavern.com&ref=&email=1&email o=jetpack&host=wptavern

Chat read-only to anonymous users. Chat with Anyone and Anywhere. Only registered users are allowed to send messages.
Loading the chat ...
97840 Register Login

Continue Reading

Previous: Here’s what changed in the new Fed statement
Next: DCD Wednesday Review|Chayora founders launch digital infra investment platform | Alaska outages |Vodafone & Three agree £15bn UK Merger

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

verde two
VERDE TWO Apartment sale
  • actress and actor
  • Afghanistan
  • airlines
  • amazon
  • America
  • android
  • apache
  • apple
  • Arab
  • australia
  • Australian Embassy
  • automotive
  • bahan bangunan
  • Bali island
  • Ban
  • banking
  • bearing
  • Brazil
  • Brunei Darussalam
  • business
  • canada
  • casino
  • China
  • cloud
  • cloudflare
  • cPanel
  • cruise
  • crypto currency
  • culture
  • currency
  • DNS
  • docker
  • eCommerce
  • economy
  • education
  • Email
  • Energy
  • england
  • entertainment
  • environment
  • Fashion
  • finance
  • Food
  • France
  • gaming
  • garden
  • Germany
  • golf
  • Golf indonesia
  • google
  • HarmonyOS
  • Health products
  • history
  • hospital
  • hotel restaurant
  • Huawei
  • human
  • IBM
  • IMF
  • india
  • Indonesia
  • instagram
  • internet
  • investment
  • Israel
  • Japan
  • jobs
  • kitchenware
  • korea
  • kubernetes
  • KVM
  • Leisure
  • limbah
  • Linux
  • Living style
  • Longhorn
  • lottery
  • machine
  • machine learning
  • machinery
  • Malaysia
  • manufacturing
  • mariadb
  • maritime
  • material building
  • medical
  • meta
  • Microsoft
  • music
  • MySQL
  • New Zealand
  • news
  • NFS
  • Nickel
  • nightclub
  • north korea
  • OBS
  • oil and gas
  • Pakistan
  • Palestine
  • Philippines
  • Photography
  • php
  • phpMyAdmin
  • private-jet
  • promotion products
  • real estate
  • Resort hotel
  • Russia
  • sanitary ware
  • search engine
  • Shopping Mal
  • singapore
  • Singapore Pools
  • software
  • south korea
  • sport
  • ssl
  • swiss
  • Technology
  • Thailand
  • tourism boards
  • travel
  • Turkish
  • Ubuntu
  • Uncategorized
  • United Arab Emirates
  • vietnam
  • virtualbox
  • virtualization
  • vmware
  • water products
  • whatsapp
  • WordPress
Register and posting news , your skills , knowledge , science , stories , experiences , etc
Copyright © All rights reserved. The tiatira is not responsible for the content of each writer / author , external sites. |