Impact
CVE-2025-48147 reveals a missing authorization flaw in the Crypto Cloud CryptoCloud - Crypto Payment Gateway plugin for WordPress. The vulnerability allows an attacker to bypass normal access controls and execute privileged actions that the plugin normally restricts, such as managing payment settings or initiating transactions. This flaw is classified as CWE-862 and can enable unauthorized users to gain elevated rights within the WordPress site.
Affected Systems
The CryptoCloud - Crypto Payment Gateway plugin, versions up through 2.1.2, is impacted. Sites running any release from the plugin’s initial version up to and including 2.1.2 are potentially vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the flaw can be exploited remotely via standard HTTP requests to the plugin’s administrative endpoints, provided the attacker can target a site hosting the vulnerable plugin. Because it allows unauthorized manipulation of payment gateway functions, the potential consequences for confidentiality, integrity, and availability of financial operations are significant. Prompt remediation is advised to mitigate the risk of unauthorized access.
OpenCVE Enrichment
EUVD