Access Control Vulnerability in Dreamfox Media Payment Gateway for WooCommerce
CVE-2024-55996
6.1MEDIUM
Key Information:
- Vendor
- WordPress
- Vendor
- CVE Published:
- 16 December 2024
Summary
CVE-2024-55996 is a critical vulnerability affecting the Dreamfox Media Payment Gateway for WooCommerce. This vulnerability arises from a missing authorization mechanism that allows attackers to exploit incorrectly configured access control settings. If successfully exploited, this could enable unauthorized access to sensitive payment information, presenting a significant risk to online merchants and their customers. The vulnerability impacts all versions of the product up to and including 3.5.6, emphasizing the urgent need for users to update their systems to mitigate potential security breaches.
Affected Version(s)
Dreamfox Media Payment gateway per Product for Woocommerce <= 3.5.6
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Mika (Patchstack Alliance)