Description
A vulnerability was identified in WonderTrader up to 0.9.9. Affected is the function _undone_qty in the library src/WtCore/TraderAdapter.h of the component Pending Order Handler. The manipulation of the argument getUndoneQty leads to enforcement of behavioral workflow. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-08-07
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The issue lies within the _undone_qty function of WonderTrader’s Pending Order Handler, where manipulating the getUndoneQty argument allows an attacker to alter the enforcement of the behavioral workflow. The effect is not execution of arbitrary code, but instead a change to how pending orders are processed, potentially enabling unauthorized order modifications or cancellations. This reflects weaknesses classified as CWE‑840 and CWE‑841.

Affected Systems

WonderTrader versions up to 0.9.9 are affected. The vulnerability exists in the library src/WtCore/TraderAdapter.h of the Pending Order Handler component. No other vendors or product versions are mentioned in the supplied data.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The description states that the attack can be carried out remotely and that an exploit is publicly available, suggesting that an external attacker could send crafted requests to the vulnerable endpoint and alter pending order processing.

Generated by OpenCVE AI on August 7, 2026 at 20:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Contact WonderTrader to obtain an official patch or update for versions up to 0.9.9
  • Restrict remote access to the pending order handler via firewall or network segmentation and enforce strict authentication
  • Implement input validation on the getUndoneQty parameter to ensure it falls within allowed ranges
  • Monitor transaction logs for abnormal pending order activity that may indicate exploitation attempts

Generated by OpenCVE AI on August 7, 2026 at 20:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in WonderTrader up to 0.9.9. Affected is the function _undone_qty in the library src/WtCore/TraderAdapter.h of the component Pending Order Handler. The manipulation of the argument getUndoneQty leads to enforcement of behavioral workflow. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title WonderTrader Pending Order TraderAdapter.h _undone_qty behavioral workflow
First Time appeared Wondertrader
Wondertrader wondertrader
Weaknesses CWE-840
CWE-841
CPEs cpe:2.3:a:wondertrader:wondertrader:*:*:*:*:*:*:*:*
Vendors & Products Wondertrader
Wondertrader wondertrader
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Wondertrader Wondertrader
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-07T21:02:09.627Z

Reserved: 2026-08-07T08:39:07.373Z

Link: CVE-2026-19213

cve-icon Vulnrichment

Updated: 2026-08-07T20:57:44.342Z

cve-icon NVD

Status : Deferred

Published: 2026-08-07T18:17:12.793

Modified: 2026-08-12T21:00:37.147

Link: CVE-2026-19213

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T20:15:04Z

Weaknesses