CVE-2024-1690
13.03.2024, 16:15
The TeraWallet Best WooCommerce Wallet System With Cashback Rewards, Partial Payment, Wallet Refunds plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the terawallet_export_user_search() function in all versions up to, and including, 1.4.10. This makes it possible for authenticated attackers, with subscriber-level access and above, to export a list of registered users and their emails.Enginsight
Vendor | Product | Version |
---|---|---|
standalonetech | terawallet | 𝑥 < 1.4.11 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References