CyberRota Analysis
AI-GeneratedThe Otter Blocks plugin for WordPress is susceptible to an Insecure Direct Object Reference vulnerability, allowing unauthenticated attackers to exploit the 'watch_checkout' function. By manipulating the product_id parameter in the Stripe checkout URL, attackers can gain access to premium products without proper payment. WordPress site administrators using this plugin should prioritize patching to mitigate potential financial losses and unauthorized access.
Original NVD Description
The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.1.7 via the 'watch_checkout' function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to pay for a lower-cost product while obtaining entitlement for a premium product by manipulating the product_id parameter independently of the price_id parameter in the Stripe checkout URL.