Description
Missing Authorization vulnerability in centangle Direct Checkout for WooCommerce Lite woo-direct-checkout-lite allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Direct Checkout for WooCommerce Lite: from n/a through <= 1.0.3.
Published: 2025-06-06
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Missing Authorization flaw in the Direct Checkout for WooCommerce Lite plugin up through version 1.0.3. It allows a user to access plugin functionality that should be restricted by access control lists, thereby enabling unauthorized operations or data exposure. This type of flaw is classified as CWE‑862 and signifies that the plugin’s internal security checks are insufficient or absent. The vendor description confirms that any functionality not properly constrained by ACLs can be used by attackers who trigger the vulnerable endpoints.

Affected Systems

The affected product is the Direct Checkout for WooCommerce Lite plugin, developed by centangle. All releases from the initial version (no starting version listed) up to and including 1.0.3 are vulnerable. Users running any of these versions on a WordPress site with WooCommerce installed are at risk.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity when viewed from a technical perspective. The EPSS score of less than 1% suggests that exploitation attempts are currently rare or difficult to detect. The vulnerability is not listed in the CISA KEV catalog. Exploitation likely occurs through a normal web request to the plugin’s endpoints, implying a remote attack vector with limited prerequisites: the ability to send requests to the WordPress site. An attacker benefiting from this flaw can gain or influence restricted functionality without having elevated privileges, potentially impacting the confidentiality or integrity of the store’s checkout process.

Generated by OpenCVE AI on April 30, 2026 at 18:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Direct Checkout for WooCommerce Lite to a version newer than 1.0.3. The latest release removes the missing authorization checks.
  • If an upgrade is not feasible, remove or disable the plugin entirely to eliminate the exposed endpoints.
  • Review the plugin’s custom code and enforce proper ACLs on all functions that perform checkout or payment processing, ensuring that only authorized roles can execute them.

Generated by OpenCVE AI on April 30, 2026 at 18:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-17185 Missing Authorization vulnerability in centangle Direct Checkout for WooCommerce Lite allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Direct Checkout for WooCommerce Lite: from n/a through 1.0.3.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in centangle Direct Checkout for WooCommerce Lite allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Direct Checkout for WooCommerce Lite: from n/a through 1.0.3. Missing Authorization vulnerability in centangle Direct Checkout for WooCommerce Lite woo-direct-checkout-lite allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Direct Checkout for WooCommerce Lite: from n/a through <= 1.0.3.
Title WordPress Direct Checkout for WooCommerce Lite <= 1.0.3 - Broken Access Control Vulnerability WordPress Direct Checkout for WooCommerce Lite plugin <= 1.0.3 - Broken Access Control Vulnerability
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Fri, 06 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 06 Jun 2025 13:15:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in centangle Direct Checkout for WooCommerce Lite allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Direct Checkout for WooCommerce Lite: from n/a through 1.0.3.
Title WordPress Direct Checkout for WooCommerce Lite <= 1.0.3 - Broken Access Control Vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:52.804Z

Reserved: 2025-03-11T08:11:02.521Z

Link: CVE-2025-29006

cve-icon Vulnrichment

Updated: 2025-06-06T15:03:58.178Z

cve-icon NVD

Status : Deferred

Published: 2025-06-06T13:15:30.810

Modified: 2026-04-23T15:26:46.320

Link: CVE-2025-29006

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T18:15:06Z

Weaknesses