Impact
The plugin suffers from a missing authorization flaw that permits arbitrary deletion of site content. This weakness, identified as CWE‑862, enables an attacker to remove posts, pages, or other records within the WordPress site, undermining data integrity and potentially causing operational disruption.
Affected Systems
The vulnerability affects the cardpaysolutions Payment Gateway Authorize.Net CIM for WooCommerce plugin, versions from the first release through version 2.1.2 inclusive.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, and the EPSS score of less than 1% suggests low current exploitation probability. The vulnerability is not listed in CISA KEV. Because the flaw allows deletion of arbitrary content, it can potentially be exploited by an attacker who has authenticated into the WordPress backend, but the requirement for authentication and use of the plugin’s administrative interface are inferred from the missing authorization. The potential impact includes irreversible data loss and site downtime if the attacker targets critical content.
OpenCVE Enrichment