Description
The Yaad Sarig Payment Gateway For WC WordPress plugin before 2.2.13 does not verify authorization or that the requesting user owns the target order in several of its order payment-processing actions, allowing any authenticated user, including subscribers, to act on and alter orders belonging to other customers.
Published: 2026-10-07
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized manipulation of customer orders
Action: Apply patch
AI Analysis

Impact

The vulnerability in the Yaad Sarig Payment Gateway For WC plugin (versions prior to 2.2.13) arises from an absence of proper authorization checks during order payment‑processing actions. This flaw allows any authenticated user—including subscribers—to access orders that do not belong to them and modify payment details. The impact is a breach of confidentiality, integrity, and potentially availability of customer data, as attackers can alter transaction records, redirect payments, or cause financial discrepancies.

Affected Systems

This issue affects the WordPress plugin Yaad Sarig Payment Gateway For WC on all installations that use a version older than 2.2.13. Administrators should verify the plugin version and update to the latest release if applicable.

Risk and Exploitability

The flaw is exploitable by any user with authenticated access to the site, making the attack vector essentially any logged‑in user. The CVSS score of 4.3 indicates a medium overall risk, and the lack of an EPSS score does not diminish the risk: an attacker can change order data without additional prerequisites. The vulnerability is not listed in the CISA KEV catalog, but its potential for financial loss and reputational damage warrants prompt remediation.

Generated by OpenCVE AI on October 7, 2026 at 11:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Yaad Sarig Payment Gateway For WC plugin to version 2.2.13 or later
  • Restrict order payment‑processing functions to administrator roles only
  • Enable detailed logging of order payment actions and regularly audit logs for unauthorized activity

Generated by OpenCVE AI on October 7, 2026 at 11:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 07 Oct 2026 10:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-639

Wed, 07 Oct 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Yaad Sarig Payment Gateway For WC WordPress plugin before 2.2.13 does not verify authorization or that the requesting user owns the target order in several of its order payment-processing actions, allowing any authenticated user, including subscribers, to act on and alter orders belonging to other customers.
Title Yaad Sarig Payment Gateway For WC < 2.2.13 - Subscriber+ Arbitrary Order Payment Manipulation via IDOR
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-07T10:09:57.910Z

Reserved: 2026-10-02T06:32:20.196Z

Link: CVE-2026-104651

cve-icon Vulnrichment

Updated: 2026-10-07T09:58:36.426Z

cve-icon NVD

Status : Received

Published: 2026-10-07T07:16:57.857

Modified: 2026-10-07T11:17:10.733

Link: CVE-2026-104651

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T11:30:16Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key