Impact
The vulnerability is an unauthenticated bypass in the Pay With MetaMask For WooCommerce – Cryptocurrency Payment Gateway plugin, allowing any user to execute a payment transaction without proper authorization. The vulnerability is a classic case of CWE‑345, where an attacker can provide permitted inputs that grant unintended privileges. Attackers could siphon cryptocurrency from a merchant’s account or generate fraudulent orders, directly compromising financial integrity and potentially leading to monetary loss.
Affected Systems
The affected product is the WordPress Pay With MetaMask For WooCommerce – Cryptocurrency Payment Gateway plugin by Narinder Singh. Versions 1.7.2 and earlier are impacted; any site running these versions of the plugin is vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, and the EPSS score is not disclosed. The vulnerability is not listed in the CISA KEV catalog. Because the bug is unauthenticated, the likely attack vector is remote – an attacker can send specially crafted requests to the plugin’s endpoint from anywhere over the internet. Retaining an older plugin version exposes merchants to financial loss until the flaw is remediated.
OpenCVE Enrichment