Unauthorized Access Flaw in Wallet System for WooCommerce by WordPress
CVE-2024-13724
What is CVE-2024-13724?
The Wallet System for WooCommerce plugin, designed for managing wallet functionalities in WordPress, presents a significant security weakness. Versions up to and including 2.6.2 are prone to unauthorized access, enabling unauthenticated attackers to exploit the system. This vulnerability allows malicious actors to illegally increase their own wallet balances, transfer funds between arbitrary users, and initiate transfer requests from other users' wallets, potentially resulting in significant financial loss and compromise of user accounts. Immediate action is recommended to mitigate risks associated with this critical flaw.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Wallet System for WooCommerce * <= 2.6.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved