Impact
The vulnerability is a missing authorization flaw that permits an attacker to spoof content on a WordPress site that uses the Payoneer Checkout plugin. Because the plugin lacks proper access checks, a malicious party can send crafted requests to overwrite or insert arbitrary HTML or text, potentially leading to misinformation or tricking users. This flaw is identified by CWE‑862 and can result in confidentiality and integrity compromise of the site’s displayed content.
Affected Systems
The issue impacts the Payoneer Checkout WordPress plugin. All installations using version 3.4.0 or earlier are affected; versions above 3.4.0 are not listed as vulnerable.
Risk and Exploitability
The CVSS score of 4.3 places this vulnerability in the low‑severity range. The EPSS score of < 1% indicates a very low probability of exploitation in the wild, and the vulnerability is not included in the CISA KEV catalog. Based on the description the vulnerability requires the attacker to be able to send requests against the plugin endpoints, which suggests a remote or local attack vector; however the exact attack path is not specified in the advisory, so the precise vector is inferred. The missing authorization condition presents a moderate risk to the integrity of site content, as an unauthenticated or limited‑privilege attacker could potentially alter information displayed to visitors.
OpenCVE Enrichment
EUVD