Impact
The plugin contains a missing authorization check that allows an attacker to execute privileged actions without proper authentication. This flaw could enable unauthorized modification of payment settings, viewing of transaction data, or other sensitive operations, potentially leading to financial loss or data exposure. The weakness falls under CWE-862, indicating a missing or incorrect authorization control.
Affected Systems
The issue affects WordPress sites that use the Peach Payments Gateway plugin version 3.3.6 or earlier. Any deployment of the plugin—regardless of theme or other plugins—remains vulnerable until the plugin is updated beyond the stated version.
Risk and Exploitability
With a CVSS score of 6.5, the vulnerability is considered moderate. The EPSS score of <1% suggests a low current likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Although the public description does not specify the exact attack vector, the missing authorization implies that an attacker with the ability to send unauthenticated or improperly authenticated HTTP requests to the plugin’s endpoints could exploit it, often requiring network access to the WordPress site and an account with administrative or editor privileges to maximize impact.
OpenCVE Enrichment