Vulnerability Description
An issue was discovered in the CardGate Payments plugin through 3.1.15 for WooCommerce. Lack of origin authentication in the IPN callback processing function in cardgate/cardgate.php allows an attacker to remotely replace critical plugin settings (merchant ID, secret key, etc.) and therefore bypass the payment process (e.g., spoof an order status by manually sending an IPN callback request with a valid signature but without real payment) and/or receive all of the subsequent payments.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cardgate | Cardgate Payments | <= 3.1.15 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/156504/WordPress-WooCommerce-CardGate-PaymeExploitThird Party AdvisoryVDB Entry
- https://github.com/cardgate/woocommerce/blob/f2111af7b1a3fd701c1c5916137f3ac0948ExploitThird Party Advisory
- https://github.com/cardgate/woocommerce/issues/18ExploitThird Party Advisory
- https://wpvulndb.com/vulnerabilities/10097Third Party Advisory
- https://www.exploit-db.com/exploits/48134ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/156504/WordPress-WooCommerce-CardGate-PaymeExploitThird Party AdvisoryVDB Entry
- https://github.com/cardgate/woocommerce/blob/f2111af7b1a3fd701c1c5916137f3ac0948ExploitThird Party Advisory
- https://github.com/cardgate/woocommerce/issues/18ExploitThird Party Advisory
- https://wpvulndb.com/vulnerabilities/10097Third Party Advisory
- https://www.exploit-db.com/exploits/48134ExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2020-8819?
CVE-2020-8819 is a vulnerability with a CVSS score of 8.1 (HIGH). An issue was discovered in the CardGate Payments plugin through 3.1.15 for WooCommerce. Lack of origin authentication in the IPN callback processing function in cardgate/cardgate.php allows an attacke...
How severe is CVE-2020-8819?
CVE-2020-8819 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-8819?
Check the references section above for vendor advisories and patch information. Affected products include: Cardgate Cardgate Payments.