Impact
The vulnerability exists because the clearOrderLogs() function in the Rede Itaú for WooCommerce plugin does not perform a capability check. This omission allows an attacker who does not have any authenticated access to the WordPress site to invoke the function and remove the Rede Order Logs metadata from all WooCommerce orders. The loss of these logs erodes the ability to audit transactions and could conceal fraudulent activity. The weakness is a missing authentication for a critical function (CWE‑306).
Affected Systems
The issue affects the WordPress plugin Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit, provided by linknacional. Versions up to and including 5.1.5 are vulnerable; any site using these releases is at risk.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk level. With an EPSS score of less than 1 %, the probability of exploitation is considered low, and the vulnerability is not currently listed in the CISA KEV catalog. An attacker can exploit the flaw by sending an unauthenticated request to the clearOrderLogs endpoint; no special privileges or additional infrastructure are required.
OpenCVE Enrichment