Access Control Vulnerability in Dreamfox Media Payment Gateway for WooCommerce
CVE-2024-55996

6.1MEDIUM

Key Information:

Vendor
WordPress
Vendor
CVE Published:
16 December 2024

Summary

CVE-2024-55996 is a critical vulnerability affecting the Dreamfox Media Payment Gateway for WooCommerce. This vulnerability arises from a missing authorization mechanism that allows attackers to exploit incorrectly configured access control settings. If successfully exploited, this could enable unauthorized access to sensitive payment information, presenting a significant risk to online merchants and their customers. The vulnerability impacts all versions of the product up to and including 3.5.6, emphasizing the urgent need for users to update their systems to mitigate potential security breaches.

Affected Version(s)

Dreamfox Media Payment gateway per Product for Woocommerce <= 3.5.6

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mika (Patchstack Alliance)
.