CVE-2026-97259 Pay with Vipps for WooCommerce 授权绕过漏洞
影响攻击者可绕过授权访问或操作未授权资源
AI 研判
该漏洞为 WordPress 插件 Pay with Vipps for WooCommerce 中的授权绕过问题,属于通过用户可控键值(IDOR 类)导致的访问控制缺陷。攻击者可利用配置不当的访问控制层级,越权访问或操作本不应被其访问的资源。
影响范围
Pay with Vipps for WooCommerce
受影响版本为 Pay with Vipps for WooCommerce 6.2.4 及之前版本(n/a 至 6.2.4)。
漏洞详情
漏洞类型为授权绕过(Authorization Bypass Through User-Controlled Key),即系统在处理请求时直接信任用户可控的键值(如订单号、用户 ID 等),未校验当前用户是否有权访问该对象。攻击者通过修改请求中的键值即可访问他人数据或执行越权操作,本质是访问控制配置不当。
利用条件与风险
利用通常只需已登录或可发起请求的低权限账户,无需特殊条件,实战中可导致越权读取订单/用户信息或执行未授权操作,风险较高。
修复建议
建议升级至 6.2.4 之后的修复版本;若暂无可用更新,应临时限制插件相关接口访问或加强服务端对象级权限校验。
原始情报
Authorization Bypass Through User-Controlled Key vulnerability in WP Hosting AS Pay with Vipps for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Pay with Vipps for WooCommerce: from n/a through 6.2.4.