These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
The File Uploads Addon for WooCommerce WordPress plugin through 1.7.6 stores customer-uploaded files in a publicly web-accessible uploads directory and the access restriction it generates is ineffective. An unauthenticated attacker who knows or guesses a file's name can retrieve customer-uploaded files directly, bypassing the File Uploads Addon for WooCommerce WordPress plugin through 1.7.6's authenticate [truncated]
The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that an incoming payment notification was confirmed in the store's configured payment environment or paid to the store's own merchant account before marking an order complete, allowing unauthenticated users to mark their own orders as paid using a genuine transaction from a payment sandbox they control.
The Checkout Field Manager (Checkout Manager) for WooCommerce WordPress plugin before 7.9.7 does not properly validate the ownership of an attachment before deleting it, allowing any authenticated user such as a customer to delete arbitrary media attachments belonging to other users. This vulnerability can disrupt WooCommerce operations and data integrity. Defenders should verify affected versions and pri [truncated]
The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not verify that the PayPal account which received a payment matches the merchant's configured account before marking the order as paid, allowing unauthenticated buyers to complete a WooCommerce order by paying the full amount to their own PayPal account instead of the merchant's.
The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not validate the payment amount or bind the PayPal order token to the order being completed on the WooCommerce order-received flow: it captures a client-supplied token and marks the order paid whenever the capture status is COMPLETED, without comparing the captured amount to the order total. This allows an attacker (unauthenticated where [truncated]
The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing and activating a plugin from a user-supplied slug through a nonce-protected AJAX action. This allows users with the Shop Manager role, who lack plugin-management capabilities, to install and activate arbitrary plugins, resulting in remote code execution.
CVE-2022-50972 is a critical remote code execution vulnerability in WooCommerce 7.1.0. The vulnerability allows attackers to execute arbitrary PHP code by injecting shell commands through the product-type parameter. This is achieved by sending requests to the class-wc-meta-box-product-images.php endpoint with unsanitized product-type values, enabling the writing of malicious PHP files to the web root. The [truncated]
The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_pay_for_order()` function in all versions up to, and including, 10.7.0. This is due to a missing order ownership or order_key verification when processing payment for an order via the `wc_stripe_pay_for_order` WC-AJAX endpoint. The function only vali [truncated]
The WooCommerce PayPal Payments plugin for WordPress contains missing authorization checks on two WC-AJAX endpoints (`ppc-create-order` and `ppc-get-order`) in versions up to and including 4.0.1. The `ppc-create-order` endpoint accepts arbitrary WooCommerce order IDs in the `pay-now` context without validating order ownership, allowing unauthenticated attackers to create PayPal orders for any WC order and [truncated]