What the vulnerability does
01Description
Unauthenticated Broken Access Control in Revolut Gateway for WooCommerce < 4.22.10 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Unauthenticated Broken Access Control in Revolut Gateway for WooCommerce < 4.22.10 versions.
Explanation of Vulnerability in Simple Terms
The Revolut Gateway for WooCommerce plugin fails to properly check user permissions before allowing access to sensitive payment gateway functions. An unauthenticated attacker can read limited payment or configuration data without logging in. Update to version 4.22.10 or later to restore proper access controls.
What an attacker can do
Read sensitive payment gateway data or configuration without authentication.
Potential impact on your site
Unauthorized users can view payment gateway settings or transaction metadata, risking credential or configuration exposure.
Conditions required to exploit
Network access to the WooCommerce site; no login or user interaction required.
Key dates
External resources
Related vulnerabilities