Impact
The Wizit Gateway for WooCommerce plugin contains a flaw in the handle_checkout_redirecturl_response function that fails to enforce authentication and authorization, allowing unauthenticated attackers to cancel any WooCommerce order by sending a crafted HTTP request with a valid order identifier. This vulnerability exists in all plugin versions up to and including 1.3.1, undermining the e‑commerce process and enabling fraud or revenue loss when orders are canceled before payment is processed.
Affected Systems
All installations of the Wizit Gateway for WooCommerce plugin up to and including version 1.3.1 are affected; versions beyond 1.3.1 contain the fix.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is inferred to be a straightforward HTTP request to the checkout redirect URL endpoint, requiring only knowledge of an existing order ID. Once the attacker submits the crafted request, the order is canceled immediately, potentially causing financial and operational damage.
OpenCVE Enrichment