Cross-Site Request Forgery (CSRF) vulnerability in TeraWallet β For WooCommerce plugin <= 1.3.24 versions.
8.8CVSS
8.8AI Score
0.001EPSS
The TeraWallet plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 1.4.3. This is due to insufficient validation of the user-controlled key on the lock_unlock_terawallet AJAX action. This makes it possible for authenticated attackers, with subscr...
4.3CVSS
4.3AI Score
0.001EPSS
Cross-Site Request Forgery (CSRF) vulnerability in StandaloneTech TeraWallet β For WooCommerce plugin <= 1.3.24 leading to plugin settings change.
4.3CVSS
5.6AI Score
0.001EPSS
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StandaloneTech TeraWallet β For WooCommerce allows Stored XSS.This issue affects TeraWallet β For WooCommerce: from n/a through 1.5.0.
5.9CVSS
6.6AI Score
0.0004EPSS