Impact
The vulnerability arises because the Payment Gateway for Redsys & WooCommerce Lite plugin does not validate the origin or authenticity of payment‑provider notifications before updating the order status to paid. An attacker can send a forged callback that triggers the plugin to mark the order as paid without a real transaction, resulting in loss of revenue and the possibility of malicious users claiming paid items or services they never purchased.
Affected Systems
All WordPress sites running the Payment Gateway for Redsys & WooCommerce Lite plugin with a version earlier than 7.0.2 are susceptible. The issue affects the Redsys payment method within the plugin, as the callback verification step is missing for that method.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.5, reflecting high severity. The EPSS score is not available, which means the current exploitation probability is unknown, but the potential impact is significant. The vulnerability is not listed in CISA’s KEV catalog. Because no authentication is required for the callback, the likely attack vector is a simple HTTP request crafted by an attacker who can cause the payment gateway to believe a transaction has been completed. Once triggered, the attacker can process their own orders as paid, leading to financial loss for the site owner.
OpenCVE Enrichment