CVE-2022-3995: TeraWallet – For WooCommerce <= 1.4.3 - Insecure Direct Object Reference
Published Nov 29, 2022
·Updated
The TeraWallet plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 1.4.3. This is due to insufficient validation of the user-controlled key on the lockunlockterawallet AJAX action. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to lock/unlock other users wallets.
Affected Software
1 affected component
StandaloneTech Terawallet Wordpress<=1.4.3
Remediation
Event History
Nov 29, 2022
CVE Published
via MITRE·08:43 PM
Data Sourced
via MITRE·08:43 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-3995?
CVE-2022-3995 is classified as a medium severity vulnerability.
2
How do I fix CVE-2022-3995?
To fix CVE-2022-3995, update the TeraWallet plugin to version 1.4.4 or later.
3
What type of vulnerability is CVE-2022-3995?
CVE-2022-3995 is an Insecure Direct Object Reference vulnerability.
4
Who is affected by CVE-2022-3995?
Authenticated attackers with subscriber-level access can exploit CVE-2022-3995.
5
What versions of TeraWallet are affected by CVE-2022-3995?
TeraWallet versions up to and including 1.4.3 are affected by CVE-2022-3995.