Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown

CVE-2025-24552

Disclosure Date: January 24, 2025 (last updated January 25, 2025)
Generation of Error Message Containing Sensitive Information vulnerability in David de Boer Paytium allows Retrieve Embedded Sensitive Data. This issue affects Paytium: from n/a through 4.4.11.
0
Attacker Value
Unknown

CVE-2024-51667

Disclosure Date: December 31, 2024 (last updated January 02, 2025)
Missing Authorization vulnerability in David de Boer Paytium.This issue affects Paytium: from n/a through 4.4.10.
0
Attacker Value
Unknown

CVE-2023-7294

Disclosure Date: October 16, 2024 (last updated October 18, 2024)
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the create_mollie_profile function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to create a mollie payment profile.
Attacker Value
Unknown

CVE-2023-7293

Disclosure Date: October 16, 2024 (last updated October 18, 2024)
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the check_mollie_account_details function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to verify the existence of a mollie account.
Attacker Value
Unknown

CVE-2023-7292

Disclosure Date: October 16, 2024 (last updated October 18, 2024)
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized notification dismissal due to a missing capability check on the paytium_notice_dismiss function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to dismiss admin notices.
Attacker Value
Unknown

CVE-2023-7291

Disclosure Date: October 16, 2024 (last updated October 18, 2024)
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the create_mollie_account function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to set up a mollie account.
Attacker Value
Unknown

CVE-2023-7290

Disclosure Date: October 16, 2024 (last updated October 18, 2024)
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the check_for_verified_profiles function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to check profile statuses.
Attacker Value
Unknown

CVE-2023-7289

Disclosure Date: October 16, 2024 (last updated October 18, 2024)
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized API key update due to a missing capability check on the paytium_sw_save_api_keys function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to change plugin API keys.
Attacker Value
Unknown

CVE-2023-7288

Disclosure Date: October 16, 2024 (last updated October 18, 2024)
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_profile_preference function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to change plugin settings.
Attacker Value
Unknown

CVE-2023-7287

Disclosure Date: October 16, 2024 (last updated October 18, 2024)
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized subscription cancellation due to a missing capability check on the pt_cancel_subscription function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to cancel a subscription to the plugin.