Impact
The vulnerability is a missing authorization check in the PlatiOnline Payments plugin, allowing users without proper privileges to alter configuration settings or potentially access sensitive transaction data. This flaw results in unauthorized manipulation of payment workflows, compromising the integrity and confidentiality of financial transactions. The weakness is categorized as CWE‑862, reflecting improper authorization enforcement.
Affected Systems
The issue affects the PlatiOnline Payments plugin for WordPress, specifically all versions from the earliest release through version 7.0.0 provided by Adrian Ladó. No later versions are listed as affected, and no specific patch level is referenced in the available data.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate risk, while the EPSS score of less than 1% suggests a low likelihood of widespread exploitation at present. The vulnerability is not listed in the CISA KEV catalog, further implying limited known usage. Likely attack vectors involve web-based interactions with the plugin’s administrative interface, exploiting the lack of role‑based access controls.
OpenCVE Enrichment
EUVD