Impact
The MStore API WordPress plugin, when at a version older than 4.21.0, fails to check with the configured payment gateway that a transaction has been approved before marking an order as fully paid. This oversight allows an attacker who does not need any authentication to trigger the payment-completion endpoints and have an arbitrary order transition to a paid state. The result is a direct financial loss to the merchant or delivery of goods/services without compensation.
Affected Systems
WordPress sites using the MStore API plugin before version 4.21.0 are vulnerable. The defect applies to all payment-completion endpoints of the plugin, regardless of the gateway selected. No specific gateway version restrictions are mentioned.
Risk and Exploitability
The vulnerability can be exploited without any credentials, so the attack surface is wide. No CVSS score is provided in the data, and EPSS is not available while the issue is not listed in the CISA KEV catalog. The lack of gateway verification makes the exploit likely to succeed once the endpoint is reachable, and the attacker can finish the transaction within the normal order lifecycle.
OpenCVE Enrichment