CVE-2024-0631
13.03.2024, 16:15
The Duitku Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the check_duitku_response function in all versions up to, and including, 2.11.4. This makes it possible for unauthenticated attackers to change the payment status of orders to failed.Enginsight
Vendor | Product | Version |
---|---|---|
duitku | duitku_payment_gateway | 𝑥 ≤ 2.11.6 |
duitku | duitku_payment_gateway | 𝑥 ≤ 2.11.4 |
𝑥
= Vulnerable software versions
References