Access violation vulnerability in Duitku Payment Gateway 2.11.4

The Duitku Payment Gateway plugin for WordPress has a security issue that allows unauthorized individuals to change payment information without proper authorization. This vulnerability exists in all versions of the plugin, up to and including version 2.11.4. It can be exploited by attackers who are not logged in to change the payment status of orders to “failed”.

Detected in:

Duitku Payment Gateway fixed vulnerable versions: >= * <= 2.11.6

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.