CVE-2024-8678
25.09.2024, 07:15
The Revolut Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /wc/v3/revolut REST API endpoint in all versions up to, and including, 4.17.3. This makes it possible for unauthenticated attackers to mark orders as completed.Enginsight
Vendor | Product | Version |
---|---|---|
revolut | revolut_gateway | 𝑥 ≤ 4.17.3 |
revolut | revolut_gateway_for_woocommerce | 𝑥 < 4.17.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration