Impact
The vulnerability in the Yaad Sarig Payment Gateway For WC plugin (versions prior to 2.2.13) arises from an absence of proper authorization checks during order payment‑processing actions. This flaw allows any authenticated user—including subscribers—to access orders that do not belong to them and modify payment details. The impact is a breach of confidentiality, integrity, and potentially availability of customer data, as attackers can alter transaction records, redirect payments, or cause financial discrepancies.
Affected Systems
This issue affects the WordPress plugin Yaad Sarig Payment Gateway For WC on all installations that use a version older than 2.2.13. Administrators should verify the plugin version and update to the latest release if applicable.
Risk and Exploitability
The flaw is exploitable by any user with authenticated access to the site, making the attack vector essentially any logged‑in user. The CVSS score of 4.3 indicates a medium overall risk, and the lack of an EPSS score does not diminish the risk: an attacker can change order data without additional prerequisites. The vulnerability is not listed in the CISA KEV catalog, but its potential for financial loss and reputational damage warrants prompt remediation.
OpenCVE Enrichment