Vulnerability CVE-2023-3525


Published: 2023-07-12

Description:
The Getnet Argentina para Woocommerce plugin for WordPress is vulnerable to authorization bypass due to missing validation on the 'webhook' function in versions up to, and including, 0.0.4. This makes it possible for unauthenticated attackers to set their payment status to 'APPROVED' without payment.

Type:

CWE-639

(Authorization Bypass Through User-Controlled Key)

 References:
https://www.wordfence.com/threat-intel/vulnerabilities/id/245e9117-ca63-458e-a094-60a759f5ec19?source=cve
https://www.youtube.com/watch?v=xTyWqh93AM0

Copyright 2026, cxsecurity.com

 

Back to Top