Impact
A missing authorization flaw in the Payrexx Payment Gateway for WooCommerce plugin enables exploitation of incorrectly configured access control security levels. The vulnerability allows an attacker to gain unauthorized access to privileged functions within the plugin, potentially leading to manipulation of payment settings or fraudulent transaction processing.
Affected Systems
The Payrexx Payment Gateway for WooCommerce plugin, versions up to and including 3.1.5, is affected. The issue applies to all installations of the plugin that rely on the default role and capability checks as implemented in those versions.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate impact. The EPSS score of less than 1% suggests a low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that an attacker could exploit this flaw by accessing the plugin’s administrative interface or by passing specially crafted requests that bypass role checks, allowing unauthorized configuration changes or fraudulent activity.
OpenCVE Enrichment
EUVD