Impact
A flaw in the Total Processing Card Payments for WooCommerce until version 7.3 fails to validate user supplied paths before constructing server‑side verification requests, and does not confirm the authenticity of the response. As a result, attackers can send unauthenticated requests that redirect the verification call to arbitrary hosts, exposing the merchant’s payment‑gateway credentials. They can also forge a success response that causes WooCommerce orders to be marked as paid without any real transaction. The likely attack vector is through unauthenticated HTTP requests to an exposed plugin endpoint, as the plugin accepts a path parameter from any visitor.
Affected Systems
The vulnerability affects the "Total processing card payments for WooCommerce" WordPress plugin for all versions up to and including 7.3. No sub‑vendor or alternative product names are listed in the available data.
Risk and Exploitability
Because the flaw can be triggered without authentication, an attacker only needs an HTTP client and knowledge of the vulnerable endpoint. The resulting information exposure (credential disclosure) can lead to compromise of the merchant’s payment gateway and theft of funds. Although a CVSS score is not provided and the EPSS value is unavailable, the potential financial impact and lack of authentication make the risk high. The instance is not currently listed in CISA’s Known Exploited Vulnerabilities catalog.
OpenCVE Enrichment