Access Control Vulnerability in Dreamfox Media Payment Gateway for WooCommerce
CVE-2024-55996

6.1MEDIUM

What is CVE-2024-55996?

CVE-2024-55996 is a critical vulnerability affecting the Dreamfox Media Payment Gateway for WooCommerce. This vulnerability arises from a missing authorization mechanism that allows attackers to exploit incorrectly configured access control settings. If successfully exploited, this could enable unauthorized access to sensitive payment information, presenting a significant risk to online merchants and their customers. The vulnerability impacts all versions of the product up to and including 3.5.6, emphasizing the urgent need for users to update their systems to mitigate potential security breaches.

Affected Version(s)

Dreamfox Media Payment gateway per Product for Woocommerce <= 3.5.6

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mika (Patchstack Alliance)
.