Sceawere

Vulnerability Detail

CVE-2026-73399UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Flutterwave WooCommerce Broken Authentication Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
3h ago
Vendor
flutterwave
Product
Flutterwave WooCommerce
Attack Type
CWE-288 Authentication Bypass Using an Alternate Path or Channel
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-08-18T15:17:07.387Z",
  "pubdate": "2026-08-18T15:17:07.387Z",
  "executiveSummary": "An unauthenticated broken authentication vulnerability has been identified in the Flutterwave WooCommerce plugin, specifically affecting versions 3.3.0 and prior. This security flaw exposes vulnerable WordPress sites running the specified plugin to severe compromise, allowing malicious actors to bypass standard authentication mechanisms entirely. The root vulnerability stems from improper validation or handling of authentication credentials and session states within the plugin's codebase, granting unauthorized users the ability to interact with privileged endpoints or execute sensitive actions without prior credential verification.\nThe risk implications of this security deficiency are critical, as successful exploitation enables unauthenticated attackers to perform actions reserved for authorized users or administrators, potentially leading to unauthorized data access, financial transaction manipulation, or full site takeover depending on the exposed functionality. Given that the vulnerability is exploitable without authentication, the attack vector is exposed to the public internet, lowering the barrier to entry for automated vulnerability scanners and malicious adversaries. Remediation requires immediate administrative action to secure the affected component, primarily through updating the plugin beyond the vulnerable version threshold or applying vendor-supplied patches where available.",
  "technicalDetails": "The vulnerability resides within the authentication and session management logic of the Flutterwave WooCommerce plugin for versions <= 3.3.0. Specifically, the flaw manifests due to inadequate verification of identity claims or flawed cryptographic implementation within the request handling lifecycle of the plugin. When unauthenticated requests reach the vulnerable component, the application fails to adequately ascertain whether the initiating entity possesses valid session tokens or cryptographic proofs of authorization before servicing the request.\nThe attack flow proceeds as follows: an unauthenticated adversary crafts a malicious HTTP request targeting the exposed endpoints or AJAX handlers managed by the Flutterwave WooCommerce plugin. Due to the lack of strict access controls and robust authentication enforcement, the vulnerable component processes the incoming payload and accepts the forged or missing authentication state as legitimate. Depending on the exact logic flaw, the application may return sensitive data, execute administrative functionalities, or process unauthorized state changes without triggering security exceptions.\nNetwork exposure is strictly external, as the plugin operates within a public-facing WordPress environment utilizing standard HTTP/HTTPS protocols. The privilege requirements for exploitation are non-existent, meaning any unauthenticated network user can initiate the attack sequence directly against the target web application. Payload behavior typically involves bypassing login boundaries or spoofing administrative context to interact with backend services managed by the plugin. Post-exploitation impact encompasses unauthorized administrative access, potential manipulation of payment processing workflows, and broader compromise of the underlying WordPress installation."
}
CVE-2026-73399: Flutterwave WooCommerce Broken Authentication Vulnerability (MEDIUM Severity, CVSS: 6.5) - Sceawere