CVE-2024-7747
MEDIUMDescription
The Wallet for WooCommerce plugin for WordPress is vulnerable to incorrect conversion between numeric types in all versions up to, and including, 1.5.6. This is due to a numerical logic flaw when transferring funds to another user. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create funds during a transfer and distribute these funds to any number of other users or their own account, rendering products free. Attackers could also request to withdraw funds if the Wallet Withdrawal extension is used and the request is approved by an administrator.
Is your site exposed to CVE-2024-7747?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| standalonetech | terawallet |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-7747? +
How severe is CVE-2024-7747? +
What products are affected by CVE-2024-7747? +
How do I check if I'm vulnerable to CVE-2024-7747? +
Related Vulnerabilities
GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through …
Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
Microsoft ODBC Driver Remote Code Execution Vulnerability
Incorrect conversion between numeric types in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.