CVE-2024-1690: TeraWallet – Best WooCommerce Wallet System With Cashback Rewards, Partial Payment, Wallet Refunds <= 1.4.10 - Missing Authorization to Authenticated (Subscriber+) User Email Export
The TeraWallet – Best WooCommerce Wallet System With Cashback Rewards, Partial Payment, Wallet Refunds plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the terawalletexportusersearch() function in all versions up to, and including, 1.4.10. This makes it possible for authenticated attackers, with subscriber-level access and above, to export a list of registered users and their emails.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1690?
CVE-2024-1690 is considered a critical vulnerability due to unauthorized access to user data.
How do I fix CVE-2024-1690?
To fix CVE-2024-1690, upgrade the TeraWallet plugin to version 1.4.11 or later.
Who is affected by CVE-2024-1690?
Users of the TeraWallet plugin for WordPress versions up to and including 1.4.10 are affected by CVE-2024-1690.
What is the impact of CVE-2024-1690?
The impact of CVE-2024-1690 includes potential unauthorized access to sensitive user information.
When was CVE-2024-1690 disclosed?
CVE-2024-1690 was disclosed in 2024, affecting all versions of TeraWallet up to 1.4.10.