Description
The Revolut Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /wc/v3/revolut REST API endpoint in all versions up to, and including, 4.17.3. This makes it possible for unauthenticated attackers to mark orders as completed.
Problem types
Product status
Any version
Timeline
| 2024-09-24: | Disclosed |
Credits
Jonas Höbenreich
Dmitry Derr
Thies Lukas
References
www.wordfence.com/...-0760-4420-b8cc-dc84cafd9b0d?source=cve
plugins.trac.wordpress.org/changeset/3153063/