GHSA-9f34-8wwr-2wjqHighCVSS 7.5
The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin before 7.0.2 does not verify...
🔗 CVE IDs covered (1)
📋 Description
The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin before 7.0.2 does not verify the authenticity of incoming payment-provider notifications for one of its payment methods before marking orders as paid, allowing unauthenticated attackers to forge a payment-confirmation callback and complete their own orders without paying.