Impact
The TabaPay Gateway WordPress plugin fails to validate the payment callback before creating a session for the order’s account. This omission enables an unauthenticated attacker to establish a session as any registered user, even an administrator, without needing valid credentials. Such an authentication bypass (CWE‑287) could result in full control of the website, theft or manipulation of user data, and potentially further exploitation within the site’s environment.
Affected Systems
WordPress sites running the TabaPay Gateway plugin version 1.4.0 or earlier are affected. The vendor is listed as Unknown in the CNA records, but the plugin is distributed as a WordPress plugin under the generic name TabaPay Gateway.
Risk and Exploitability
With a CVSS score of 9.8, the vulnerability poses a critical severity. The EPSS score of less than 1% suggests a current low probability of exploitation, and it is not yet listed in the CISA KEV catalog. Nonetheless, the lack of any authentication requirement for the callback endpoint indicates a potential attack vector. Based on the description, it is inferred that a remote attacker can send a crafted callback request to the site, gain administrative access, and compromise site integrity. The combination of high severity and simple exploitation path warrants urgent attention.
OpenCVE Enrichment