Impact
The vulnerability is a Missing Authorization issue in the iCount Payment Gateway plugin, allowing functions to be accessed without proper access control checks. The affected functionality is not properly constrained by ACLs, meaning an attacker could potentially invoke privileged payment operations or view sensitive settings.
Affected Systems
iCount iCount Payment Gateway plugin for WordPress, versions up through and including 2.0.7.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while an EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in CISA KEV. The likely attack vector is a web request to the plugin’s endpoints, exploiting the missing authorization check, without requiring elevated privileges beyond those granted to a standard user of the site.
OpenCVE Enrichment
EUVD