Impact
The vulnerability is a Server‑Side Request Forgery flaw that enables authenticated users with Subscriber or higher privileges to trigger web requests to arbitrary URLs from the WordPress application. This can expose sensitive internal services or be used to modify internal data. The weakness is mapped to CWE‑918.
Affected Systems
WordPress sites running the PayMaster for WooCommerce plugin by qazomardok, any installed version up to and including 0.4.31.
Risk and Exploitability
The reported CVSS score of 6.4 indicates moderate severity, while an EPSS score of less than 1% suggests a very low likelihood of exploitation. The flaw is not listed in the CISA KEV catalog. Attackers must be authenticated with at least Subscriber level, implying potential insider threat or compromised accounts as the prerequisite.
OpenCVE Enrichment
EUVD