Unknown · Wondertrader · CVE-2026-19208
**Name of the Vulnerable Software and Affected Versions**
WonderTrader versions prior to 1.0.0
**Description**
A remote attack is possible through the manipulation of the `FID JYLB` argument within the `TraderDD::queryTrades()` function located in the src/TraderDD/TraderDD.cpp file. This action results in the enforcement of a behavioral workflow. The attack is characterized by high complexity and is considered difficult to exploit.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary mitigation, restrict access to the `TraderDD::queryTrades()` function.