Impact
Unspecified WordPress plugin, NOWPayments for WooCommerce versions 1.4.0 and earlier, suffers from an unauthenticated broken access control flaw described as CWE-862. This means that any user who can reach the site may be able to invoke privileged functions without proper authentication. The description does not enumerate specific consequences, but the nature of the flaw indicates the possibility of unauthorized changes to core plugin settings or taking actions normally restricted to authenticated users.
Affected Systems
The affected product is the CoderPress NOWPayments for WooCommerce plugin. Any WordPress site that has installed a version of this plugin 1.4.0 or older is vulnerable.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity level. The EPSS score of a low probability of exploitation in the short term, and the flaw is not listed in authenticated, an attacker who can reach the WordPress site over the network could potentially exploit it.
OpenCVE Enrichment