Impact
The BlueSnap Payment Gateway for WooCommerce plugin fails to enforce proper authorization when processing Instant Payment Notification (IPN) requests. It relies on a plugin‑level wrapper that accepts IP addresses derived from user‑controllable HTTP headers, allowing an unauthenticated attacker to spoof a legitimate BlueSnap IP address and send forged IPN payloads. By doing so, an attacker can arbitrarily alter order statuses—including marking orders as paid, failed, refunded, or on‑hold—without any legitimate credentials. This vulnerability enables unauthorized financial state changes that could have serious business and reputational repercussions.
Affected Systems
WordPress sites that use the BlueSnap Payment Gateway for WooCommerce plugin version 3.4.0 or earlier, including all releases up to and including 3.4.0, operated by any merchant with an active BlueSnap integration.
Risk and Exploitability
The severity score of 7.5 indicates a high‑risk vulnerability, while the EPSS score of less than 1% suggests that, at the time of this assessment, the likelihood of public exploitation is low. The flaw is not listed in the CISA KEV catalog. Attackers would likely exploit the flaw remotely by sending forged IPN traffic that appears to originate from an approved BlueSnap IP address, bypassing the plugin's IP whitelisting logic and manipulating order states without authentication.
OpenCVE Enrichment