Standalonetech develops TerraWallet, a web-based financial application whose vulnerability profile centers on application-layer flaws spanning authentication, access control, and input handling. The recurring weakness classes—including cross-site request forgery, authorization bypass, cross-site scripting, SQL injection, and numeric-type conversion errors—reflect the common attack surface of web applications managing sensitive transactions and user data. Current severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Standalonetech over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-36401HIGH Cross-Site Request Forgery (CSRF) vulnerability in TeraWallet – For WooCommerce plugin <= 1.3.24 versions. | Feb 2, 2023 | 8.8 | 27 | NO | NO |
CVE-2024-6353MEDIUM The Wallet for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'search[value]' parameter in all versions up to, and including, 1.5.4 due to insufficient esc | Jul 12, 2024 | 6.5 | 21 | NO | NO |
CVE-2024-7747MEDIUM The Wallet for WooCommerce plugin for WordPress is vulnerable to incorrect conversion between numeric types in all versions up to, and including, 1.5.6. This is due to a numerical | Nov 28, 2024 | 6.5 | 19 | NO | NO |
CVE-2022-3995MEDIUM The TeraWallet plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 1.4.3. This is due to insufficient validation of the user-co | Nov 29, 2022 | 4.3 | 19 | NO | NO |
CVE-2022-40198MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in StandaloneTech TeraWallet – For WooCommerce plugin <= 1.3.24 leading to plugin settings change. | Mar 1, 2023 | 4.3 | 17 | NO | NO |
CVE-2024-32584MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StandaloneTech TeraWallet – For WooCommerce allows Stored XSS.This issue affec | Apr 18, 2024 | 4.8 | 16 | NO | NO |
CVE-2024-1690MEDIUM The TeraWallet – Best WooCommerce Wallet System With Cashback Rewards, Partial Payment, Wallet Refunds plugin for WordPress is vulnerable to unauthorized access of data due to a mi | Mar 13, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Standalonetech.
Media articles that mention a CVE ID that affects a product developed by Standalonetech — matched by CVE ID, not by vendor name.