SKT PayPal for WooCommerce Payment Bypass Vulnerability
Vulnerability
A vulnerability allowing payment bypass has been identified in the SKT PayPal for WooCommerce plugin for WordPress, affecting all versions through 1.4. The issue arises because the plugin relies solely on client-side validation instead of implementing necessary server-side checks when processing payments. This flaw enables unauthenticated attackers to complete purchases without making actual payments.
Impact
Exploitation of this vulnerability allows for unauthorized purchases to be processed as confirmed transactions, without any payment being made.
Remediation
Users can update to version 1.5 or a newer patched version to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
