PT-2024-16441 · WordPress · Yaad Sarig Payment Gateway For Wc

Brokenac Ignore

·

Published

2024-11-20

·

Updated

2024-11-20

·

CVE-2024-10665

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Yaad Sarig Payment Gateway For WC plugin for WordPress versions up to, and including, 2.2.4
Description The issue is related to a missing capability check on the yaadpay view log callback() and yaadpay delete log callback() functions. This allows authenticated attackers with Subscriber-level access and above to view and delete logs, resulting in unauthorized modification and access of data.
Recommendations For versions up to, and including, 2.2.4, consider disabling the yaadpay view log callback() and yaadpay delete log callback() functions until a patch is available to prevent unauthorized access and modification of logs.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-10665

Affected Products

Yaad Sarig Payment Gateway For Wc