Once an attacker has a valid credit card number and expiration date, there are only 10⁴ = 10,000 four-digit security codes possible, which the attacker tries with parallel requests to hundreds of websites. Each website gives the attacker at least a few tries to enter valid credit card information.
Worst case, it takes only 10,000 parallel requests to guess the correct security code. Worst case.
I don't know whether to cringe or laugh at this.