Access violation vulnerability in PayHere Payment Gateway Plugin for WooCommerce 2.3.9

The PayHere Payment Gateway Plugin for WooCommerce, which is used with WordPress, has a security issue that allows unauthorized changes to be made to data. This is because the way it checks for valid responses is not effective, and this vulnerability exists in all versions up to 2.3.9. As a result, attackers without proper authorization can alter the status of pending orders in WooCommerce, making them appear as paid, completed, or on hold.

Detected in:

PayHere Payment Gateway open vulnerable versions: >= * <= 2.3.9

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.