CVE-2023-35049

WordPress WooCommerce Stripe Payment Gateway plugin <= 7.4.0 - Unauthenticated Broken Access Control vulnerability

Missing Authorization vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue affects WooCommerce Stripe Payment Gateway: from n/a through 7.4.0.


We have discovered 14,572 live websites that are affected by CVE-2023-35049.

Test my site




Affected Software

Product  WooCommerce Stripe Payment Gateway
Category Wordpress Plugins
Vulnerable Domains14,572 live websites (25.27% of WooCommerce Stripe Payment Gateway install base)
Vulnerable Versions
  • from 0 through 7.4
Vulnerable Versions Count141 versions ( 81.03% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Jun 19, 2024
  • Updated - Aug 2, 2024

Credits

  • Rafie Muhammad (Patchstack) (finder)

CVE-2023-35049 usage by Country

United States5,748 websites



France1,897 websites
Germany1,374 websites
GB1,203 websites
Australia536 websites
Spain522 websites
Italy413 websites
Japan330 websites
Switzerland313 websites
Canada244 websites

CVE-2023-35049 usage by TLD

.com8,076 websites
.co.uk1,000 websites
.fr659 websites
.com.au639 websites
.org353 websites
.it339 websites
.de302 websites
.es268 websites
.net224 websites
.ca211 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-35049

Top websites that are affected by CVE-2023-35049. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.com United States*,***
***********.net United States**,***
**********.com United States**,***
************.com United States**,***
**************.org United States**,***
*********.***.uk United States**,***
********.org United States**,***
**********.com France**,***
*******.**.uk GB**,***
******.com United States**,***
See full domain list

FAQ

CVE-2023-35049 is Missing Authorization in WooCommerce Stripe Payment Gateway
A total of 14,572 websites have been identified as vulnerable to CVE-2023-35049, discovered through global website indexing conducted by WebTechSurvey.
WooCommerce Stripe Payment Gateway is susceptible to CVE-2023-35049 vulnerability.
WooCommerce Stripe Payment Gateway versions before, and including, 7.4 are vulnerable to CVE-2023-35049.