Red team work and penetration testing in financial environment.

oolongeya
Offensive Security Engineer
Red team work and pen testing at a financial company in South Korea.
started Web Hacking CTF in 2022 and Bug Bounty in 2026.
•Experience
Security Consulting Track
•Vulnerabilities
- The plugin does not properly handle batch requests, which could allow unauthenticated users to make a logged in admin call non store/WC REST endpoints, and create arbitrary admin users via a CSRF attack for example.
- By taking over admin privileges, restricted features can be controlled.
- By taking over admin privileges, restricted features can be controlled.
•Bug Bounty
- bypassing authorization checks on an internal write endpoint.
- A malicious phishing link under a PayPal domain can be generated and redirect users to a malicious site when clicked.
- The plugin does not properly handle batch requests, which could allow unauthenticated users to make a logged in admin call non store/WC REST endpoints, and create arbitrary admin users via a CSRF attack for example.
- CSRF is possible via a nonce-bypass request.