Description
Unauthenticated Bypass Vulnerability in Pay With MetaMask For WooCommerce – Cryptocurrency Payment Gateway <= 1.7.2 versions.
Published: 2026-10-10
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthenticated payment bypass
Action: Apply patch
AI Analysis

Impact

The vulnerability is an unauthenticated bypass in the Pay With MetaMask For WooCommerce – Cryptocurrency Payment Gateway plugin, allowing any user to execute a payment transaction without proper authorization. The vulnerability is a classic case of CWE‑345, where an attacker can provide permitted inputs that grant unintended privileges. Attackers could siphon cryptocurrency from a merchant’s account or generate fraudulent orders, directly compromising financial integrity and potentially leading to monetary loss.

Affected Systems

The affected product is the WordPress Pay With MetaMask For WooCommerce – Cryptocurrency Payment Gateway plugin by Narinder Singh. Versions 1.7.2 and earlier are impacted; any site running these versions of the plugin is vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity, and the EPSS score is not disclosed. The vulnerability is not listed in the CISA KEV catalog. Because the bug is unauthenticated, the likely attack vector is remote – an attacker can send specially crafted requests to the plugin’s endpoint from anywhere over the internet. Retaining an older plugin version exposes merchants to financial loss until the flaw is remediated.

Generated by OpenCVE AI on October 10, 2026 at 20:20 UTC.

Remediation

Vendor Solution

Update the WordPress Pay With MetaMask For WooCommerce – Cryptocurrency Payment Gateway plugin to the latest available version (at least 1.7.3).


OpenCVE Recommended Actions

  • Update the Pay With MetaMask For WooCommerce – Cryptocurrency Payment Gateway plugin to version 1.7.3 or later.
  • Disable the plugin on all WordPress sites until the update is applied or reversed.
  • After updating, monitor transaction logs for any unexpected or suspicious cryptocurrency transfers and ensure that only authenticated users can initiate payments.

Generated by OpenCVE AI on October 10, 2026 at 20:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Bypass Vulnerability in Pay With MetaMask For WooCommerce – Cryptocurrency Payment Gateway <= 1.7.2 versions.
Title WordPress Pay With MetaMask For WooCommerce – Cryptocurrency Payment Gateway plugin <= 1.7.2 - Bypass Vulnerability vulnerability
Weaknesses CWE-345
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-10T19:36:23.815Z

Reserved: 2026-10-08T00:19:19.565Z

Link: CVE-2026-107420

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T20:16:32.387

Modified: 2026-10-10T20:16:32.387

Link: CVE-2026-107420

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T20:30:06Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity