Impact
The vulnerability arises because the WordPress plugin PayPlus Payment Gateway before version 8.2.2 does not verify user authorization or order ownership in a particular AJAX action exposed to unauthenticated users. As a result, an attacker can request that action and receive the secret order key for any WooCommerce order. Depending on the site configuration that key can also be used to alter the order status, potentially defrauding the site owner or end users. The weakness is a lack of authorization checks (CWE‑862).
Affected Systems
WordPress sites running the PayPlus Payment Gateway plugin with a version older than 8.2.2. No additional vendor or product details are provided beyond the plugin name and affected version range.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity risk. The EPSS score is less than 1 %, suggesting a low probability of exploitation at the present time, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw by accessing the vulnerable AJAX endpoint from any unauthenticated browser or script, sending the required parameters to retrieve the order key or modify order status. No special privileges or network access are required beyond visibility of the WordPress site.
OpenCVE Enrichment