Revolut's vulnerability footprint centers on its payment gateway integration for WooCommerce, a narrowly scoped product serving merchants processing transactions through the platform. The observed weakness in this payment-processing context involves missing authorization controls, which poses a risk to transaction integrity and customer data exposure in e-commerce deployments. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Revolut over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-8678MEDIUM The Revolut Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /wc/v3/revolut REST API endpoin | Sep 25, 2024 | 5.3 | 17 | NO | NO |
CVE-2023-52224MEDIUM Missing Authorization vulnerability in Revolut Revolut Gateway for WooCommerce.This issue affects Revolut Gateway for WooCommerce: from n/a through 4.9.7. | Jun 11, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Revolut.
Media articles that mention a CVE ID that affects a product developed by Revolut — matched by CVE ID, not by vendor name.