Impact
The vulnerability is a missing authorization flaw in the ksher thailand Ksher payment plugin, allowing attackers to bypass intended access controls. An attacker who can reach the plugin’s interfaces can potentially manipulate or create payment transactions without authentication, violating confidentiality and integrity of financial operations. The root weakness is identified as CWE‑862, standard for missing authorization.
Affected Systems
WordPress sites running ksher thailand’s Ksher payment plugin version 1.1.2 or earlier are affected. All installations of the plugin should be examined regardless of additional security layers, as the issue spans the entire plugin up to the listed limit.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score of less than 1% suggests exploitation is currently rare. The vulnerability is not listed in the CISA KEV catalog. Based on the description, there is no explicit authentication or network restriction mentioned, so the likely attack vector is remote exploitation of exposed plugin endpoints without prior authentication. An attacker could exploit the flaw from an external network, provided they can send requests to the WordPress site.
OpenCVE Enrichment
EUVD