Impact
An authentication bypass flaw allows attackers to abuse the PayU India plugin on WordPress sites, giving them the ability to assume the identities of legitimate accounts. The weakness is categorized as CWE-288, indicating a failure to enforce proper authentication controls. This can lead to full control of the affected WordPress installation.
Affected Systems
Any WordPress installation running the PayU India plugin version earlier than 3.8.8 is vulnerable. The issue impacts the PayU India product across all versions that are not yet patched. Site administrators should verify the current plugin version immediately.
Risk and Exploitability
With a CVSS score of 9.8 the vulnerability is considered critical. The EPSS score of less than 1% suggests that exploitation is currently unlikely, but the risk remains high because the flaw would allow remote attackers to bypass authentication outright. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is via an alternate HTTP path or channel that bypasses the standard login process, allowing a remote attacker to gain account access with no further prerequisites.
OpenCVE Enrichment
EUVD