Unauthorized Payment Data Deletion Vulnerability in WP-Recall Plugin

CVE-2024-1175
5.3MEDIUM

Key Information

Vendor
WPpost
Status
WP-recall – Registration, Profile, Commerce & More
Vendor
CVE Published:
6 June 2024

Summary

The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'delete_payment' function in all versions up to, and including, 16.26.6. This makes it possible for unauthenticated attackers to delete arbitrary payments.

Affected Version(s)

WP-Recall – Registration, Profile, Commerce & More <= 16.26.6

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published.

  • Disclosed

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database

Credit

Francesco Carlucci
.