Impact
The vulnerability is a missing authorization flaw that permits exploitation of incorrectly configured access control security levels within the Knitpay UPI QR Code Payment Gateway for WooCommerce plugin. The flaw allows an attacker to bypass normal permission checks, potentially modifying or retrieving sensitive data, or performing unintended actions on the e‑commerce site. The weakness is a classic Broken Access Control issue (CWE-862).
Affected Systems
The flaw affects the Knitpay UPI QR Code Payment Gateway for WooCommerce plugin through version 1.5.1, inclusive of all earlier releases. Sites running this plugin are at risk regardless of the broader WordPress installation.
Risk and Exploitability
Based on the description, it is inferred that the likely attack vector is via the plugin's administrative interface where no proper authentication is enforced; an attacker who can reach the site could trigger unauthorized actions without needing elevated credentials. The CVSS score is 6.5, indicating a medium severity level. The EPSS score is below 1 %, suggesting a low likelihood of exploitation in the wild at present. It is not listed in CISA's KEV catalog, so there is no current evidence of active exploitation.
OpenCVE Enrichment