Impact
The plugin contains a cross‑site request forgery weakness that lets an attacker force a logged‑in user to submit payment‑gateway requests without their consent. A successfully executed request can trigger payment processing, modify transaction data or create fraudulent orders, thereby compromising the integrity of the e‑commerce transaction flow. This flaw maps to CWE‑352 and carries a CVSS score of 7.1, indicating a significant risk when exploited.
Affected Systems
WordPress sites running axima Pays – WooCommerce Payment Gateway versions up through 2.6 are susceptible. The vulnerability affects all installations that have not updated beyond version 2.6, regardless of the WordPress core or WooCommerce version.
Risk and Exploitability
With an EPSS value of less than 1 % the current probability of real‑world exploitation is low, but the threat is still present on the web. The flaw can be triggered by a crafted URL or embedded link that an unsuspecting user visits, so no special privileges or technical skills are required beyond normal web browsing. Because the exploit is delivered via the web interface, it is harmless to administrators who only maintain the plugins but poses a real risk to end users. The vulnerability is not listed in the CISA KEV catalog as of this analysis.
OpenCVE Enrichment
EUVD