Impact
The vulnerability is an unauthenticated Insecure Direct Object Reference that allows an attacker to bypass normal authorization controls and obtain or modify protected resources such as order details or payment data. The weakness, identified as CWE-639, permits direct request manipulation to target arbitrary objects without the need for a valid user session. This could lead to data leakage or unapproved changes to transaction records.
Affected Systems
The affected product is the WordPress Mercado Pago payments for WooCommerce plugin, versions 8.9.0 and earlier, distributed by Mercado Pago.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, and no EPSS score is available. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires no authentication and likely involves sending crafted URLs or form submissions to reference hidden or sequential resource identifiers. While the impact is limited to data confidentiality and integrity of orders, the lack of authentication requirement makes it readily exploitable in a publicly exposed environment.
OpenCVE Enrichment