Impact
Unspecified WordPress plugin, NOWPayments for WooCommerce versions 1.4.0 and earlier, suffers from an unauthenticated broken access control flaw described as CWE-862. This means that any user who can reach the site may be able to invoke privileged functions without proper authentication. The description does not enumerate specific consequences, but the nature of the flaw indicates the possibility of unauthorized changes to core plugin settings or taking actions normally restricted to authenticated users.
Affected Systems
The affected product is the CoderPress NOWPayments for WooCommerce plugin. Any WordPress site that has installed a version of this plugin 1.4.0 or older is vulnerable.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity level. The EPSS score of a low probability of exploitation in the short term, and the flaw is not listed in the CISA KEV catalog. Because the vulnerability is unauthenticated, an attacker who can reach the WordPress site over the network could potentially exploit it. The exact entry point is not specified, but the typical characteristics of plugin‑based access control issues imply that the REST API or admin interface might be involved. This inference is based on common web‑application vulnerability patterns rather than explicit details in the CVE description.
OpenCVE Enrichment