PT-2026-96658 · WordPress · Handily
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Handily plugin for WordPress versions prior to 1.0.4
Description
Missing authorization checks allow unauthenticated attackers to modify Stripe payment configuration settings. By manipulating payment settings parameters, an attacker can change publishable keys, secret keys, email addresses, success URLs, and cancel URLs, potentially redirecting payments to their own Stripe accounts.
Recommendations
Update the Handily plugin for WordPress to version 1.0.4 or later.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Handily