Impact
The plugin contains a missing authorization flaw that allows an attacker to perform an Insecure Direct Object Reference, granting access to other users’ payment records and possibly affecting order or refund data. This can compromise the confidentiality and integrity of sensitive transaction details.
Affected Systems
The vulnerability affects the Mollie Payments for WooCommerce WordPress plugin up to and including version 8.0.2, provided by the Mollie vendor.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of <1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker could exploit the IDOR by manipulating URLs or API requests to access or modify restricted payment objects, but no widespread public exploits are known.
OpenCVE Enrichment
EUVD