Impact
The vulnerability is a missing authorization flaw that allows unauthorized users to perform privileged actions within the WooCommerce Payment Gateway bKash for WC plugin. Lack of proper access control means an attacker could manipulate payment processing settings, potentially altering transaction amounts or redirecting funds. The weakness maps to CWE‑862.
Affected Systems
The issue affects Kapil Paul’s Payment Gateway bKash for WC plugin for all releases from the earliest known version up to and including 3.1.0. WordPress sites running any of these plugin versions are therefore potentially vulnerable.
Risk and Exploitability
The vulnerability has a CVSS score of 5.3, indicating moderate severity, and an EPSS score of less than 1%, implying a low probability of exploitation at this time. It is not currently listed in CISA’s KEV catalog. Exploitation would presumably occur through the plugin’s web interface, requiring some form of authenticated access, although the exact attack vector is not explicitly documented and is inferred from the description of incorrect access control. Because the flaw permits unauthorized privileged operations, a successful attack could compromise the integrity of payment processing on affected sites.
OpenCVE Enrichment