#VU19046 Security restrictions bypass in WooCommerce PayPal Checkout Payment Gateway - CVE-2019-7441
Published: July 8, 2019 / Updated: June 17, 2021
WooCommerce PayPal Checkout Payment Gateway
woocommercereport
Description
The vulnerability allows a remote attacker to bypass certain security restrictions.
The vulnerability exists due to application does not perform validation of the attacker-controlled data, assuming that data is valid and safe. A remote attacker can tamper with parameters, passed to the application, and change its flow, e.g. purchase and item for lower price.