Description
Missing Authorization vulnerability in Virtuaria Virtuaria PagBank / PagSeguro para Woocommerce virtuaria-pagseguro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Virtuaria PagBank / PagSeguro para Woocommerce: from n/a through <= 3.6.3.
Published: 2025-12-09
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization flaw that allows an attacker to perform actions or access resources that should be restricted to authorized users or privileged roles. It stems from incorrectly configured access control security levels within the Virtuaria PagBank / PagSeguro para WooCommerce plugin. The weakness corresponds to CWE‑862, indicating that the plugin does not enforce the necessary privilege checks before executing sensitive operations.

Affected Systems

The issue affects all installations of the Virtuaria PagBank / PagSeguro para WooCommerce plugin from the earliest release up to version 3.6.3. WordPress sites using this plugin for payment processing are potentially vulnerable, regardless of the WordPress core or theme versions. No further details on additional affected components are provided.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate vulnerability. The EPSS score is reported to be less than 1 %, suggesting that the likelihood of exploitation remains low, and the vulnerability is not listed in CISA’s KEV catalog. The attack path is inferred to involve exploitation of improperly protected plugin endpoints; an attacker would need to reach those endpoints, which may require some form of authenticated or partially privileged access. Once the attacker succeeds, they may perform actions that should be restricted, as the missing authorization flaw permits access to privileged operations.

Generated by OpenCVE AI on April 30, 2026 at 05:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Virtuaria PagBank / PagSeguro para WooCommerce plugin to the latest available version ensuring the missing authorization fix is applied
  • Restrict access to the plugin’s administrative and payment processing endpoints by configuring role‑based capabilities and ensuring only authorized users can invoke them
  • Verify that WordPress and WooCommerce are running the latest secure releases and that default user privileges are minimized; disable or remove the plugin if it is not essential to site operation

Generated by OpenCVE AI on April 30, 2026 at 05:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 11 Dec 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 10 Dec 2025 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Woocommerce
Woocommerce woocommerce
Wordpress
Wordpress wordpress
Vendors & Products Woocommerce
Woocommerce woocommerce
Wordpress
Wordpress wordpress

Tue, 09 Dec 2025 15:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Virtuaria Virtuaria PagBank / PagSeguro para Woocommerce virtuaria-pagseguro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Virtuaria PagBank / PagSeguro para Woocommerce: from n/a through <= 3.6.3.
Title WordPress Virtuaria PagBank / PagSeguro para Woocommerce plugin <= 3.6.3 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Woocommerce Woocommerce
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:03.386Z

Reserved: 2025-10-07T15:41:52.361Z

Link: CVE-2025-62151

cve-icon Vulnrichment

Updated: 2025-12-11T18:57:08.831Z

cve-icon NVD

Status : Deferred

Published: 2025-12-09T16:18:01.453

Modified: 2026-04-27T18:16:26.070

Link: CVE-2025-62151

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T05:00:14Z

Weaknesses