Impact
The vulnerability is a missing authorization flaw that allows an attacker to abuse incorrectly configured access control security levels within the Frisbii Pay WordPress plugin. It enables privileged actions such as viewing or altering payment configurations, potentially leading to unauthorized financial manipulations or data exposure. The flaw is classified as CWE-862, indicating a lack of required authority checks.
Affected Systems
WordPress sites running the Frisbii Pay reepay-checkout-gateway plugin version 1.8.2.1 or earlier. The affected component is the Frisbii Pay plugin, which is available through the Frisbii vendor.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% suggests a low- to very low probability of exploitation at this moment, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is web‑based, likely via requests to the plugin’s administrative endpoints, and could be carried out by users with minimal or no authentication depending on server configuration. Exploitation requires that the attacker can reach the plugin’s control interfaces and thatadequate role checks are missing.
OpenCVE Enrichment
EUVD