CVE-2024-30527
WordPress WP Express Checkout plugin <= 2.3.7 - Price Manipulation vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Improper Validation of Specified Quantity in Input vulnerability in Tips and Tricks HQ WP Express Checkout (Accept PayPal Payments) allows Manipulating Hidden Fields.This issue affects WP Express Checkout (Accept PayPal Payments): from n/a through 2.3.7.
Vulnerabilidad de validaciĆ³n incorrecta de la cantidad especificada en la entrada en Tips and Tricks HQ WP Express Checkout (Accept PayPal Payments) permite manipular campos ocultos. Este problema afecta a WP Express Checkout (Accept PayPal Payments): desde n/a hasta 2.3.7.
The WP Express Checkout (Accept PayPal Payments) plugin for WordPress is vulnerable to price manipulation in all versions up to, and including, 2.3.7. This is due to insufficient validation on the pricing data being passed to the server. This makes it possible for unauthenticated attackers to modify the price of bookings.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-03-27 CVE Reserved
- 2024-03-29 CVE Published
- 2024-05-18 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-348: Use of Less Trusted Source
- CWE-1284: Improper Validation of Specified Quantity in Input
CAPEC
- CAPEC-162: Manipulating Hidden Fields
References (1)
URL | Tag | Source |
---|---|---|
https://patchstack.com/database/vulnerability/wp-express-checkout/wordpress-wp-express-checkout-plugin-2-3-7-price-manipulation-vulnerability?_s_id=cve | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wp Express Checkout Search vendor "Wp Express Checkout" | Wp Express Checkout Search vendor "Wp Express Checkout" for product "Wp Express Checkout" | >= 0.0.0 <= 2.3.7 Search vendor "Wp Express Checkout" for product "Wp Express Checkout" and version " >= 0.0.0 <= 2.3.7" | en |
Affected
|