Description
WordPress Plugin Stripe For WooCommerce is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently configure their account to use other site users unique STRIPE identifier and make purchases with their payment accounts. WordPress Plugin Stripe For WooCommerce versions between 3.0.0 and (including) 3.3.9 are vulnerable.
Remediation
Update to plugin version 3.3.10 or latest
References
https://www.wordfence.com/vulnerability-advisories/#CVE-2021-39347
https://plugins.svn.wordpress.org/woo-stripe-payment/trunk/readme.txt
Related Vulnerabilities
PHP Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2006-0207)
OpenSSL Use After Free Vulnerability (CVE-2016-6309)
WordPress Plugin UpiCRM-Free WordPress CRM and Lead Management Information Disclosure (2.1.8.5)
WordPress Plugin Click to Copy Grab Box Multiple Cross-Site Scripting Vulnerabilities (0.1.1)