Impact
Missing authorization controls in the Digages Direct Payments WP plugin allow an attacker without proper privileges to access or manipulate payment‑related features. This broken access control can enable unauthorized users to view or modify payment records, initiate transactions, or otherwise exploit the plugin's functionality. The vulnerability is classified as CWE‑862, indicative of missing user privilege checks.
Affected Systems
The affected product is Digages Direct Payments WP plugin, versions up through 1.3.2. Any WordPress website that has this plugin installed and has not upgraded beyond 1.3.2 may be vulnerable. The plugin is likely included in sites requiring payment processing via WordPress.
Risk and Exploitability
Because the CVSS score is 4.3, the impact is considered moderate; however the EPSS score of less than 1% suggests a very low exploitation probability at this time. The vulnerability is not listed in the CISA KEV catalog, indicating it has not been observed in widespread exploitation. Attackers would most likely target the plugin through its exposed administrative endpoints, potentially by crafting a request that bypasses role checks. While no public exploits are documented, administrators should treat this as a legitimate risk from lack of access control.
OpenCVE Enrichment