Unauthenticated Broken Access Control in Revolut Gateway for WooCommerce
CVE-2026-73353

5.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
13 August 2026

What is CVE-2026-73353?

A security flaw has been identified in the Revolut Gateway for WooCommerce plugin, specifically in versions prior to 4.22.10. This vulnerability allows unauthenticated users to gain access to restricted functions, posing a significant risk to the integrity of the e-commerce setup. The flaw could lead to unauthorized transactions or data exposure, urging immediate attention from site administrators to mitigate potential threats.

Affected Version(s)

Revolut Gateway for WooCommerce < 4.22.10

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lee chul woong | Patchstack Bug Bounty Program
.