Impact
The PayPlus Payment Gateway WordPress plugin before version 8.2.2 contains an authorization weakness that allows any unauthenticated user to execute a privileged AJAX action. Through this endpoint, an attacker can modify payment‑related metadata on arbitrary WooCommerce orders, potentially altering amounts, statuses, or payment methods. This flaw directly compromises the integrity of order data and could be used to defraud merchants or customers.
Affected Systems
WordPress sites using the PayPlus Payment Gateway plugin with a version older than 8.2.2. The vendor listed is unknown, but the plugin is widely used in e‑commerce WordPress installations that rely on WooCommerce.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, and the EPSS score of less than 1% suggests a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is any user able to reach the plugin’s AJAX endpoint over the network; the attacker simply needs to send an HTTP request without authentication to tamper with order metadata.
OpenCVE Enrichment