nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-37871 CVE-2023-37871
HIGH
WordPress WooCommerce GoCardless Gateway Plugin <= 2.5.6 is vulnerable to Insecure Direct Object References (IDOR)
Record summary
CVE-2023-37871 has a selected CVSS score of 8.2 (high).
Description
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce GoCardless.This issue affects GoCardless: from n/a through 2.5.6.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
GoCardlessBrowse WooCommerce / GoCardlessDefault status: unaffected | CVE List | Through 2.5.6 | affected |
References
2patchstack.comvdb entry
https://patchstack.com/database/vulnerability/woocommerce-gateway-gocardless/wordpress-woocommerce-gocardless-gateway-plugin-2-5-6-unauthenticated-insecure-direct-object-references-idor-vulnerability?_s_id=cve