Impact
The vulnerability exists in the WooCommerce REST API endpoint that updates order status. A missing capability check allows any visitor, including unauthenticated users, to mark an order as processed or completed.
Affected Systems
All installations of the Japanized for WooCommerce plugin by Shoheitanaka running version 2.7.17 or earlier on WordPress with WooCommerce. The flaw affects only the plugin's payment gateway endpoint for the paidy gateway, but it impacts any WooCommerce site that uses the affected plugin.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% shows a very low likelihood of exploitation at the time of this analysis. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is unauthenticated HTTP requests to the plugin’s order REST endpoint, which can be made by anyone with access to the site’s public URLs.
OpenCVE Enrichment