Impact
The Airwallex Online Payments Gateway plugin allows an attacker to forge a payment notification because the plugin does not verify that the notification originates from the payment provider when a webhook secret has not been configured. The missing authentication check lets an unauthenticated user mark orders as paid without actually completing a payment. This flaw can undermine financial integrity and lead to unauthorized revenue loss.
Affected Systems
The vulnerability affects WordPress sites that use the Airwallex Online Payments Gateway plugin version 1.35.x or earlier. It is specifically tied to the plugin’s handling of incoming payment notifications and requires no special credentials to exploit.
Risk and Exploitability
With a CVSS score of 5.3, the vulnerability is considered moderate. No EPSS score is available, and the issue is not listed in CISA’s KEV catalog, suggesting limited public exploitation knowledge. The likely attack vector is remote, as an attacker can simply send a forged webhook to the site’s endpoint without prior authentication. Exploitation requires that the attacker can reach the WordPress site and that the plugin is running an affected version without a configured webhook secret.
OpenCVE Enrichment