Rede Itaú for WooCommerce Payment PIX Credit Card and Debit Missing Authorization Vulnerability

Vulnerability

A vulnerability exists in the Rede Itaú for WooCommerce Payment PIX, Credit Card and Debit plugin, affecting all versions up to and including 5.1.2. The issue arises from a lack of proper capability checks in the clearOrderLogs() function, allowing unauthenticated attackers to delete Rede Order Logs metadata from all WooCommerce orders.

Impact

Exploitation of this vulnerability allows for unauthorized deletion of order log metadata, which could disrupt order management and transaction records.

Reproduction

The vulnerability can be reproduced by sending a DELETE request to the '/redeIntegration/clearOrderLogs' endpoint without authentication. This request will remove the 'lknWcRedeOrderLogs' metadata from all WooCommerce orders.

Remediation

No known patch is available. It is recommended to review the vulnerability details and consider uninstalling the affected plugin.

Added: Jan 16, 2026, 7:18 AM
Updated: Jan 16, 2026, 7:18 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
8.4
remediation
0.0
relevance
2.1
threat
4.8
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.