PT-2025-5104 · WordPress · Wp Service Payment Form With Authorize.Net

·

CVE-2025-23804

·

Publicado

2025-01-16

·

Atualizado

2025-01-17

CVSS v3.1

7.1

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions WP Service Payment Form With Authorize.net versions n/a through 2.6.0
Description The issue is a Cross-Site Request Forgery (CSRF) vulnerability that allows Reflected XSS. This means an attacker can trick a user into performing unintended actions on a web application that the user is authenticated to. The vulnerability is present in the WP Service Payment Form With Authorize.net plugin, allowing for reflected XSS attacks. No information is provided about the estimated number of potentially affected devices or real-world incidents where this issue was exploited.
Recommendations For versions n/a through 2.6.0, update to a version later than 2.6.0 to resolve the issue. At the moment, there is no information about additional mitigation measures.

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-23804

Produtos afetados

Wp Service Payment Form With Authorize.Net