Impact
The vulnerability is an unauthenticated broken access control flaw in the Revolut Gateway for WooCommerce plugin versions prior to 4.22.10. An attacker who can reach the plugin’s web interface could potentially view or alter sensitive transaction data, modify payment settings, or perform actions that should be reserved for authenticated users. The weakness is identified as CWE-862, which signifies that the application fails to enforce proper authorization. No additional exploitation code or privilege escalation steps are disclosed in the available data.
Affected Systems
WordPress sites using the Revolut Gateway for WooCommerce plugin earlier than version 4.22.10 are affected. The plugin is distributed under the vendor name revolutbusiness and appears in the WordPress plugin repository. No further sub-component or external service information is provided.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate risk, and the EPSS score is not available, so the current exploitation likelihood cannot be quantified. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is the public web interface of the plugin, where an unauthenticated user can send crafted requests to access protected resources. No additional prerequisites such as elevated privileges or network access are mentioned, suggesting that the flaw could be exploited from the internet without prior authentication.
OpenCVE Enrichment