Unauthorized Access Flaw in Wallet System for WooCommerce by WordPress
CVE-2024-13724
4.3MEDIUM
Summary
The Wallet System for WooCommerce plugin, designed for managing wallet functionalities in WordPress, presents a significant security weakness. Versions up to and including 2.6.2 are prone to unauthorized access, enabling unauthenticated attackers to exploit the system. This vulnerability allows malicious actors to illegally increase their own wallet balances, transfer funds between arbitrary users, and initiate transfer requests from other users' wallets, potentially resulting in significant financial loss and compromise of user accounts. Immediate action is recommended to mitigate risks associated with this critical flaw.
Affected Version(s)
Wallet System for WooCommerce * <= 2.6.2
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Tim Coen