Description
Cross-Site Request Forgery (CSRF) vulnerability in codemstory 워드프레스 결제 심플페이 pgall-for-woocommerce allows Cross Site Request Forgery.This issue affects 워드프레스 결제 심플페이: from n/a through <= 5.2.11.
Published: 2025-05-07
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Cross‑Site Request Forgery (CSRF) is present in the WordPress 결제 심플페이 pgall‑for‑woocommerce plugin. An authenticated user can be induced to issue unintended requests to the plugin’s endpoints, allowing attackers to perform arbitrary operations such as modifying payment settings, initiating fraudulent transactions, or altering user data. The flaw stems from a lack of proper CSRF protection for state‑changing operations, corresponding to CWE‑352.

Affected Systems

The vulnerability affects the WordPress 결제 심플페이 pgall‑for‑woocommerce plugin version 5.2.11 and earlier. The plugin is distributed by codemstory and is commonly installed on WooCommerce‑based WordPress sites that utilize the SimplePay payment gateway. No other products or vendors are mentioned.

Risk and Exploitability

The CVSS score of 5.4 indicates a moderate severity, and the EPSS score of less than 1% reflects a low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitability requires a victim to be an authenticated user who visits a malicious page crafted by the attacker; the attacker can then trigger unwanted requests through the vulnerable plugin’s endpoints without user consent. Due to the nature of CSRF, an attacker cannot directly access a target system but can abuse the victim’s credentials to change critical payment configuration or perform unauthorized operations.

Generated by OpenCVE AI on April 30, 2026 at 20:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WordPress 결제 심플페이 pgall‑for‑woocommerce plugin to the latest available version that removes the CSRF flaw.
  • If an update is not yet available, uninstall or disable the plugin completely to eliminate the attack surface.
  • Until a patch is released, add custom nonce checks to any forms that trigger state‑changing actions or restrict those actions to the site administrator role only.

Generated by OpenCVE AI on April 30, 2026 at 20:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-13737 Cross-Site Request Forgery (CSRF) vulnerability in codemstory 워드프레스 결제 심플페이 allows Cross Site Request Forgery. This issue affects 워드프레스 결제 심플페이: from n/a through 5.2.11.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in codemstory 워드프레스 결제 심플페이 allows Cross Site Request Forgery. This issue affects 워드프레스 결제 심플페이: from n/a through 5.2.11. Cross-Site Request Forgery (CSRF) vulnerability in codemstory 워드프레스 결제 심플페이 pgall-for-woocommerce allows Cross Site Request Forgery.This issue affects 워드프레스 결제 심플페이: from n/a through <= 5.2.11.
Title WordPress 워드프레스 결제 심플페이 <= 5.2.11 - Cross Site Request Forgery (CSRF) Vulnerability WordPress 워드프레스 결제 심플페이 plugin <= 5.2.11 - Cross Site Request Forgery (CSRF) Vulnerability
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L'}


Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00018}

epss

{'score': 0.0002}


Wed, 07 May 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 May 2025 14:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in codemstory 워드프레스 결제 심플페이 allows Cross Site Request Forgery. This issue affects 워드프레스 결제 심플페이: from n/a through 5.2.11.
Title WordPress 워드프레스 결제 심플페이 <= 5.2.11 - Cross Site Request Forgery (CSRF) Vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:48.585Z

Reserved: 2025-05-07T10:45:20.229Z

Link: CVE-2025-47661

cve-icon Vulnrichment

Updated: 2025-05-07T17:19:07.622Z

cve-icon NVD

Status : Deferred

Published: 2025-05-07T15:16:18.513

Modified: 2026-04-23T15:30:42.027

Link: CVE-2025-47661

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T20:30:26Z

Weaknesses