Impact
The Integrate PhonePe with WooCommerce plugin for WordPress allows an unauthenticated attacker to send a payment‑completion request that re‑uses a previously valid transaction ID. Because the plugin does not verify that the transaction belongs to the order being marked, the attacker can cause the order status to change to ‘paid’ even though no genuine payment has occurred. This vulnerability arises from a lack of proper authentication and authorization checks (CWE-345, CWE-639).
Affected Systems
WordPress installations that have the Integrate PhonePe with WooCommerce plugin version 1.2.1 or earlier are affected. All such sites that process orders through this plugin are at risk, regardless of additional security controls elsewhere.
Risk and Exploitability
The CVSS score of 7.5 classifies the flaw as high severity. The EPSS score of < 1% indicates a very low exploitation probability at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the issue remotely by sending unauthenticated HTTP requests that reuse a valid transaction ID; once successful, arbitrary orders can be marked as paid, leading to financial loss and fulfillment errors.
OpenCVE Enrichment