Impact
The vulnerability is a missing authorization flaw that allows attackers to access privileged functionality of the PeachPay Payments plugin when it is incorrectly configured. Exploiting this flaw can let an unauthenticated or low‑privileged user perform actions that should be restricted, potentially leading to unauthorized payment processing or data exposure. The weakness falls under CWE‑862, highlighting the lack of proper access control checks.
Affected Systems
The issue affects the PeachPay Payments WordPress plugin for WooCommerce, including all versions up to and including 1.117.4. Any website that has installed a vulnerable version of this plugin is at risk, regardless of the WordPress or WooCommerce version.
Risk and Exploitability
This moderate‑severity flaw, with a CVSS score of 5.3, is considered low risk in terms of likelihood (EPSS <1%) and has not been reported in the CISA KEV catalog. The primary attack vector is the web interface of the WordPress site, where a crafted request to a plugin endpoint bypasses normal authorization checks.
OpenCVE Enrichment
EUVD