CVE-2024-10665: Yaad Sarig Payment Gateway For WC <= 2.2.4 - Missing Authorization to Authenticated (Subscriber+) Log Read/Deletion
The Yaad Sarig Payment Gateway For WC plugin for WordPress is vulnerable to unauthorized modification & access of data due to a missing capability check on the yaadpayviewlogcallback() and yaadpaydeletelogcallback() functions in all versions up to, and including, 2.2.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view and delete logs.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10665?
CVE-2024-10665 is considered a high severity vulnerability due to its potential for unauthorized data modification and access.
How do I fix CVE-2024-10665?
To fix CVE-2024-10665, update the Yaad Sarig Payment Gateway for WooCommerce plugin to the latest version beyond 2.2.4 where the vulnerability is patched.
What versions are affected by CVE-2024-10665?
CVE-2024-10665 affects all versions of the Yaad Sarig Payment Gateway for WooCommerce up to and including version 2.2.4.
What functions are involved in CVE-2024-10665?
CVE-2024-10665 involves unauthorized modification and access via the yaadpay_view_log_callback() and yaadpay_delete_log_callback() functions.
Who is the vendor for CVE-2024-10665?
The vendor for CVE-2024-10665 is Yaad Sarig, which developed the Payment Gateway for WooCommerce plugin.