Description
Unauthenticated Broken Access Control in NOWPayments for WooCommerce <= 1.4.0 versions.
Published: 2026-07-02
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Unspecified WordPress plugin, NOWPayments for WooCommerce versions 1.4.0 and earlier, suffers from an unauthenticated broken access control flaw described as CWE-862. This means that any user who can reach the site may be able to invoke privileged functions without proper authentication. The description does not enumerate specific consequences, but the nature of the flaw indicates the possibility of unauthorized changes to core plugin settings or taking actions normally restricted to authenticated users.

Affected Systems

The affected product is the CoderPress NOWPayments for WooCommerce plugin. Any WordPress site that has installed a version of this plugin 1.4.0 or older is vulnerable.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity level. The EPSS score of a low probability of exploitation in the short term, and the flaw is not listed in the CISA KEV catalog. Because the vulnerability is unauthenticated, an attacker who can reach the WordPress site over the network could potentially exploit it. The exact entry point is not specified, but the typical characteristics of plugin‑based access control issues imply that the REST API or admin interface might be involved. This inference is based on common web‑application vulnerability patterns rather than explicit details in the CVE description.

Generated by OpenCVE AI on July 21, 2026 at 12:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade NOWPayments for WooCommerce to the latest version that contains the fix for the broken access control flaw.
  • If an immediate upgrade is not possible, restrict public access to the plugin’s admin or REST endpoints by configuring to deny unauthenticated requests.
  • Enable logging and audit trails for WooCommerce configuration changes to detect any unauthorized modifications after remediation.

Generated by OpenCVE AI on July 21, 2026 at 12:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Coderpress
Coderpress nowpayments For Woocommerce
Wordpress
Wordpress wordpress
Vendors & Products Coderpress
Coderpress nowpayments For Woocommerce
Wordpress
Wordpress wordpress

Thu, 02 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in NOWPayments for WooCommerce <= 1.4.0 versions.
Title WordPress NOWPayments for WooCommerce plugin <= 1.4.0 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Coderpress Nowpayments For Woocommerce
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-02T12:11:44.427Z

Reserved: 2026-04-07T08:24:32.861Z

Link: CVE-2026-39448

cve-icon Vulnrichment

Updated: 2026-07-02T12:11:38.839Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T12:00:05Z

Weaknesses