Impact
The Total Processing Card Payments for WooCommerce plugin, up to and including version 7.3, does not guard against user‑supplied path values when creating a server‑side verification request, nor does it verify that the response originates from the legitimate payment gateway. Consequently an attacker can perform unauthenticated server‑side request forgery (SSRF) to any host, causing the plugin to disclose the merchant’s payment‑gateway credentials. In addition, the plugin accepts a forged "success" response, enabling arbitrary WooCommerce orders to be marked as paid with no actual transaction. These weaknesses map to CWE‑918 (Server‑Side Request Forgery).
Affected Systems
The vulnerability exists in the "Total Processing Card Payments for WooCommerce" WordPress plugin for all releases through version 7.3. It is relevant to any WordPress site that has installed this plugin and has not upgraded beyond the stated version. No further sub‑vendor or alternative product names are recorded.
Risk and Exploitability
Since authentication is not required to trigger the flaw, an attacker only needs to issue an HTTP request to the plugin’s exposed endpoint. The high CVSS score of 9.1 reflects the potential for financial loss and credential compromise, while the EPSS score of less than 1% suggests a low current exploitation probability but does not negate the severity. The vulnerability is not listed in CISA’s KEV catalog, yet it can result in both immediate financial fraud through order forgery and long‑term exposure of gateway keys that could allow theft of future payments.
OpenCVE Enrichment