CVE-2024-1718
MEDIUMCheckout Cielo for WooCommerce <1.1.0 - Info Disclosure
Title source: llmDescription
The Claudio Sanches – Checkout Cielo for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to insufficient payment validation in the update_order_status() function in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to update the status of orders to paid bypassing payment.
Scores
CVSS v3
5.3
EPSS
0.0009
EPSS Percentile
25.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-345
Status
published
Products (1)
claudiosanches/Claudio Sanches – Checkout Cielo for WooCommerce
< 1.1.0
Published
Jun 04, 2024
Tracked Since
Feb 18, 2026