CVE-2024-30527: WordPress WP Express Checkout plugin <= 2.3.7 - Price Manipulation vulnerability
Improper Validation of Specified Quantity in Input vulnerability in Tips and Tricks HQ WP Express Checkout (Accept PayPal Payments) allows Manipulating Hidden Fields.This issue affects WP Express Checkout (Accept PayPal Payments): from n/a through 2.3.7.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-30527?
The severity of CVE-2024-30527 is considered high due to its potential for manipulating financial transactions.
How do I fix CVE-2024-30527?
To fix CVE-2024-30527, update the WP Express Checkout plugin to version 2.3.8 or later.
What versions are affected by CVE-2024-30527?
CVE-2024-30527 affects WP Express Checkout versions up to and including 2.3.7.
What type of vulnerability is CVE-2024-30527?
CVE-2024-30527 is an improper validation vulnerability that allows manipulation of hidden fields in the payment process.
Who is the vendor for CVE-2024-30527?
The vendor for CVE-2024-30527 is Tips and Tricks HQ, associated with the WP Express Checkout plugin.