Description
WordPress Plugin Stripe For WooCommerce is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently configure their account to use other site users unique STRIPE identifier and make purchases with their payment accounts. WordPress Plugin Stripe For WooCommerce versions between 3.0.0 and (including) 3.3.9 are vulnerable.
Remediation
Update to plugin version 3.3.10 or latest
References
https://www.wordfence.com/vulnerability-advisories/#CVE-2021-39347
https://plugins.svn.wordpress.org/woo-stripe-payment/trunk/readme.txt
Related Vulnerabilities
PrestaShop Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2022-46158)
WordPress Plugin My Category Order Cross-Site Scripting (4.3)
TYPO3 URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2010-3661)
WordPress Plugin WP-Contact Multiple Cross-Site Scripting Vulnerabilities (1.0)