PT-2026-52806 · Funnelkit+1 · Funnelkit Payment Gateway For Stripe Woocommerce+1
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
FunnelKit Payment Gateway for Stripe WooCommerce versions prior to 1.14.0.4
Description
An unauthenticated Cross-Site Request Forgery (CSRF) issue exists in the FunnelKit Payment Gateway for Stripe WooCommerce plugin for WordPress. This occurs due to missing or incorrect nonce validation—a security token used to verify that a request was intentionally sent by the user—within a function. This allows an attacker to perform unauthorized actions by tricking a site administrator into clicking a malicious link.
Recommendations
Update the plugin to a version newer than 1.14.0.3.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Funnelkit Payment Gateway For Stripe Woocommerce
Funnelkit-Stripe-Woo-Payment-Gateway