PT-2024-28191 · Woocommerce · Hitpay Payment Gateway For Woocommerce

Joshua Chan

·

Published

2024-08-13

·

Updated

2024-08-17

·

CVE-2024-38747

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions HitPay Payment Gateway for WooCommerce versions n/a through 4.1.3
Description The issue affects the HitPay Payment Gateway for WooCommerce, allowing unauthorized access to sensitive information due to improperly constrained functionality by Access Control Lists (ACLs). This enables accessing functionality not properly restricted.
Recommendations For versions n/a through 4.1.3, update to a version later than 4.1.3 to resolve the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-38747

Affected Products

Hitpay Payment Gateway For Woocommerce