Impact
The vulnerability is a missing authorization flaw that permits an attacker to interact with the admin interfaces of the Easy Payment Payment Gateway for PayPal on WooCommerce plugin. If exploited, the attacker could view or modify payment gateway settings and potentially redirect payments or view sensitive configuration data, compromising integrity and confidentiality of transaction processing.
Affected Systems
WordPress sites that use the Easy Payment Payment Gateway for PayPal on WooCommerce plugin, specifically versions through 9.0.53. The plugin may be installed on any WooCommerce-enabled WordPress site where the PayPal payment option is active.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score of less than 1% suggests the probability of exploitation is currently low, and the vulnerability is not listed in CISA’s KEV catalog. However, because the flaw involves broken access control, an attacker who can obtain or guess existing administrator credentials—or who can trick a legitimate admin into using a compromised session—could exploit the vulnerability. In the absence of additional mitigations, the risk remains limited to sites with exposed administrative interfaces.
OpenCVE Enrichment