Impact
The vulnerability resides in the Epeken All Kurir for Woocommerce plugin version 2.1.2 and earlier, where the code accepts a payment‑confirmation request without verifying that it comes from the legitimate order owner or confirming that a payment has been processed. The result is that anyone who can reach the endpoint can mark any arbitrary order as confirmed, and if the site is configured to treat confirmed orders as paid, an unauthenticated attacker can also generate a paid status. This flaw triggers a breach of confidentiality of financial data, integrity of order records, and availability of proper payment processing.
Affected Systems
The plugin is used within WordPress e‑commerce sites, specifically the Epeken All Kurir integration for WooCommerce. Any installation using version 2.1.2 or earlier is vulnerable. Site administrators and users of the Woocommerce platform should verify the plugin version in use.
Risk and Exploitability
The exploit is likely carried out by sending an unauthenticated request to the payment‑confirmation endpoint exposed by the plugin. Because no authentication checks are performed, the attack can succeed without any user credentials. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating that public exploitation data is limited. Nonetheless, the CVSS definition would classify this as a high‑severity flaw due to the ease of exploitation and the potential for financial damage.
OpenCVE Enrichment