Unauthorized Access Flaw in Wallet System for WooCommerce by WordPress
CVE-2024-13724
4.3MEDIUM
What is CVE-2024-13724?
The Wallet System for WooCommerce plugin, designed for managing wallet functionalities in WordPress, presents a significant security weakness. Versions up to and including 2.6.2 are prone to unauthorized access, enabling unauthenticated attackers to exploit the system. This vulnerability allows malicious actors to illegally increase their own wallet balances, transfer funds between arbitrary users, and initiate transfer requests from other users' wallets, potentially resulting in significant financial loss and compromise of user accounts. Immediate action is recommended to mitigate risks associated with this critical flaw.
Affected Version(s)
Wallet System for WooCommerce * <= 2.6.2