Description
The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to tamper with the payment-related metadata of arbitrary WooCommerce orders.
Published: 2026-07-20
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The PayPlus Payment Gateway WordPress plugin before version 8.2.2 contains an authorization weakness that allows any unauthenticated user to execute a privileged AJAX action. Through this endpoint, an attacker can modify payment‑related metadata on arbitrary WooCommerce orders, potentially altering amounts, statuses, or payment methods. This flaw directly compromises the integrity of order data and could be used to defraud merchants or customers.

Affected Systems

WordPress sites using the PayPlus Payment Gateway plugin with a version older than 8.2.2. The vendor listed is unknown, but the plugin is widely used in e‑commerce WordPress installations that rely on WooCommerce.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity, and the EPSS score of less than 1% suggests a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is any user able to reach the plugin’s AJAX endpoint over the network; the attacker simply needs to send an HTTP request without authentication to tamper with order metadata.

Generated by OpenCVE AI on July 30, 2026 at 19:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the PayPlus Payment Gateway plugin to version 8.2.2 or later, which eliminates the unauthorized AJAX endpoint.
  • Remove or disable any legacy files or interfaces that expose the old AJAX action, ensuring only the current, secure code is present on the server.
  • Restrict unauthenticated access to the plugin’s endpoints with a web‑application firewall or server‑level rules, ensuring only authenticated users can interact with order‑payment metadata.

Generated by OpenCVE AI on July 30, 2026 at 19:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Payplus
Payplus payplus Payment Gateway
Wordpress
Wordpress wordpress
Vendors & Products Payplus
Payplus payplus Payment Gateway
Wordpress
Wordpress wordpress

Mon, 20 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 20 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Description The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to tamper with the payment-related metadata of arbitrary WooCommerce orders.
Title PayPlus Payment Gateway < 8.2.2 - Unauthenticated Order Payment Metadata Tampering
References

Subscriptions

Payplus Payplus Payment Gateway
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-20T15:00:38.378Z

Reserved: 2026-06-23T09:47:52.530Z

Link: CVE-2026-12972

cve-icon Vulnrichment

Updated: 2026-07-20T15:00:29.985Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T10:00:03Z

Weaknesses