Impact
The OneClick Chat to Order plugin for WordPress is affected by an unauthorized modification vulnerability (CWE-862). The plugin fails to verify that an authenticated user has permission to change phone number settings in the wa_order_number_save_number_field function. A malicious Editor or higher level user can alter the phone numbers used for WhatsApp orders, causing customer orders and communications to be redirected to attacker-controlled numbers. This flaw does not provide code execution but enables malicious modification of configuration data, potentially allowing fraud and loss of revenue.
Affected Systems
The vendor walterpimen publishes the OneClick Chat to Order plugin. Versions up to and including 1.0.9 are vulnerable. Updating to any release newer than 1.0.9 removes the verification issue.
Risk and Exploitability
The CVSS score is 2.7, indicating a low severity flaw. The EPSS score is less than 1%, implying a very low probability of exploitation in the wild, and it is not listed in the CISA KEV catalog. The likely attack vector is through the WordPress administrative interface where a user with Editor or higher capability can access plugin settings. Because the flaw requires prior authenticated access it is not exploitable by unauthenticated users, but any site where Editors have approval authority is at risk.
OpenCVE Enrichment