Unauthorized Access Flaw in Wallet System for WooCommerce by WordPress
CVE-2024-13724

4.3MEDIUM

Key Information:

Vendor
WordPress
Vendor
CVE Published:
4 March 2025

Summary

The Wallet System for WooCommerce plugin, designed for managing wallet functionalities in WordPress, presents a significant security weakness. Versions up to and including 2.6.2 are prone to unauthorized access, enabling unauthenticated attackers to exploit the system. This vulnerability allows malicious actors to illegally increase their own wallet balances, transfer funds between arbitrary users, and initiate transfer requests from other users' wallets, potentially resulting in significant financial loss and compromise of user accounts. Immediate action is recommended to mitigate risks associated with this critical flaw.

Affected Version(s)

Wallet System for WooCommerce * <= 2.6.2

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tim Coen
.