CVE-2024-13724: Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction <= 2.6.2 - Missing Authorization
The Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction plugin for WordPress is vulnerable to unauthorized access to functionality in all versions up to, and including, 2.6.2. This makes it possible for unauthenticated attackers to increase their own wallet balance, transfer balances between arbitrary users and initiate transfer requests from other users' wallets.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13724?
CVE-2024-13724 has been classified as a medium severity vulnerability due to the potential for unauthorized access.
How do I fix CVE-2024-13724?
To fix CVE-2024-13724, update the Wallet System for WooCommerce plugin to version 2.6.3 or later.
What types of attackers can exploit CVE-2024-13724?
CVE-2024-13724 can be exploited by unauthenticated attackers who can access certain functionalities.
Which versions of the Wallet System for WooCommerce are affected by CVE-2024-13724?
All versions of the Wallet System for WooCommerce up to and including 2.6.2 are affected by CVE-2024-13724.
What functionality is exposed by CVE-2024-13724?
CVE-2024-13724 allows unauthorized access to sensitive functionalities within the Wallet System for WooCommerce.