Sceawere

Vulnerability Detail

CVE-2026-73353UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Revolut Gateway Broken Access Control

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
7h ago
Vendor
revolutbusiness
Product
Revolut Gateway for WooCommerce
Attack Type
CWE-862 Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Broken Access Control in Revolut Gateway for WooCommerce < 4.22.10 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-08-13T14:17:13.140Z",
  "pubdate": "2026-08-13T14:17:13.140Z",
  "executiveSummary": "An unauthenticated broken access control vulnerability has been identified in the Revolut Gateway for WooCommerce plugin affecting versions prior to 4.22.10. This security flaw allows unauthenticated remote attackers to interact with vulnerable backend endpoints or perform unauthorized actions reserved for privileged users or system processes. The vulnerability exposes the payment gateway integration to potential manipulation, bypassing intended security controls enforced by the application architecture. The risk implications include potential data exposure, unauthorized state changes, or transactional interference within the WordPress and WooCommerce environment. Exploitation requires network access to the target WordPress installation with the vulnerable Revolut Gateway plugin activated, but does not necessitate prior authentication or specialized user privileges. Remediation requires updating the Revolut Gateway for WooCommerce plugin to version 4.22.10 or later, where proper access control checks are enforced on sensitive endpoints.",
  "technicalDetails": "The vulnerability stems from insufficient or absent authorization checks within specific request handlers or endpoints implemented by the Revolut Gateway for WooCommerce plugin in versions < 4.22.10. In software architectures relying on access control mechanisms, endpoints intended for internal callbacks, administrative tasks, or state synchronization must rigorously validate the identity and authorization level of the requesting entity. In this instance, the vulnerable component fails to verify whether the incoming HTTP request originates from an authorized context or a legitimate authenticated user with appropriate administrative privileges.\nFrom a network exposure perspective, the vulnerable endpoints are accessible over standard HTTP/HTTPS protocols via the public-facing WordPress REST API, AJAX handlers, or custom plugin-defined URL routing mechanisms. Because the access control enforcement is missing or improperly implemented, an unauthenticated attacker can send crafted HTTP requests directly to the vulnerable component without supplying valid session tokens, cookies, or API credentials.\nThe attack flow typically proceeds as follows: First, the attacker identifies the exposed endpoint associated with the Revolut Gateway for WooCommerce plugin through reconnaissance or public vulnerability intelligence. Second, the attacker crafts a malicious HTTP request targeting this endpoint, bypassing client-side restrictions or authentication barriers. Third, because the underlying backend logic lacks requisite authorization validation, the application processes the input parameters and executes the associated functionality. Depending on the exact logic exposed by the flawed endpoint, the payload behavior may result in unauthorized data retrieval, modification of gateway configurations, or execution of privileged operations.\nThe root cause is classified under improper authorization and broken access control patterns, where trust is implicitly granted based on the request URI rather than explicit cryptographic verification or role-based access control checks. The affected component is specific to the Revolut Gateway for WooCommerce codebase handling unauthenticated incoming requests. Post-exploitation impact varies based on the specific capabilities exposed by the flawed handler, potentially leading to unauthorized transactional manipulation, disclosure of sensitive gateway telemetry, or broader compromise of the e-commerce processing workflow."
}
CVE-2026-73353: Revolut Gateway Broken Access Control (MEDIUM Severity, CVSS: 5.3) - Sceawere