Impact
The vulnerability in the Welcart e‑Commerce WordPress plugin permits an unauthenticated user to forge a settlement callback. By sending a crafted request containing an order number and a status flag, a malicious actor can switch an order from unpaid to settled without any signature, amount verification, or origin check. This flaw allows an attacker to trigger fulfillment for orders they have not paid for, leading to financial loss and inventory mismanagement.
Affected Systems
All installations of the Welcart e‑Commerce plugin with a version earlier than 2.11.33. The vulnerability is present in any site that has not applied the latest plugin update. No specific vendor or product version list beyond the version threshold.
Risk and Exploitability
The CVSS score of 5.3 denotes moderate impact, and the EPSS score is not available, indicating insufficient data on exploit likelihood. The vulnerability is not listed in the CISA KEV catalog. Because the flaw can be triggered via unauthenticated HTTP requests to the settlement callback endpoint, an attacker only needs to know a valid order number and can manipulate the status flag without authentication, making exploitation straightforward. Attacks could occur from any location that can reach the WordPress site, and there are no known mitigations beyond patching.
OpenCVE Enrichment