What the vulnerability does
01Description
Missing Authorization vulnerability in Revolut Revolut Gateway for WooCommerce.This issue affects Revolut Gateway for WooCommerce: from n/a through 4.9.7.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
What the vulnerability does
Missing Authorization vulnerability in Revolut Revolut Gateway for WooCommerce.This issue affects Revolut Gateway for WooCommerce: from n/a through 4.9.7.
Explanation of Vulnerability in Simple Terms
The Revolut Gateway for WooCommerce plugin through version 4.9.7 lacks proper authorization checks on certain functions. A logged-in user with low privileges can trigger actions they should not have access to, potentially disrupting site availability. Update to a version newer than 4.9.7 to resolve this issue.
What an attacker can do
A low-privilege logged-in user can trigger unauthorized actions that degrade site availability.
Potential impact on your site
Authenticated users may disrupt payment processing or site operations without proper permission controls.
Conditions required to exploit
Attacker must have a low-privilege account on the WooCommerce site (e.g., customer or subscriber role).
Key dates
External resources
Related vulnerabilities