Impact
The flaw exists in the Epeken All Kurir for WooCommerce plugin up to version 2.1.4 where the code accepts a payment‑confirmation request without verifying the request originates from the legitimate order owner or that any payment has actually occurred. This omission reflects a CWE‑287 Authentication Failure and enables unauthenticated attackers to mark any order as confirmed, and in a non‑default configuration to also set it to paid. The result is a severe compromise of order integrity and a potential for billing fraud.
Affected Systems
The Epeken All Kurir integration is used on WordPress e‑commerce sites to collect courier information for WooCommerce. Any installation of the plugin version 2.1.4 or earlier is affected. Administrators and site owners should verify the plugin version and apply available updates.
Risk and Exploitability
Based on the description, the likely attack vector is an unauthenticated POST request to the plugin's payment‑confirmation endpoint. Because the plugin performs no authentication or ownership checks, the attack can succeed from any external source. The EPSS score is reported as less than 1%, indicating a very low exploitation probability. The CVSS score of 5.9 denotes a medium severity due to ease of use and potential financial impact. The vulnerability is not listed in the CISA KEV catalog, but its presence still warrants prompt action.
OpenCVE Enrichment