Impact
The vulnerability is a missing authorization flaw that allows unauthorized users to access protected functions within the UnitechPay WordPress plugin. This broken access control can lead to exposure of sensitive data, unauthorized transaction handling, or privilege escalation depending on the actions exposed by the plugin. The weakness corresponds to the Missing Authorization issue defined by CWE‑862.
Affected Systems
The flaw affects the UnitechPay plugin from Unitech Web, used on WordPress sites. Any installation of the plugin with a version number up to and including 1.0.2 is vulnerable. The issue spans the entire plugin across all releases from the earliest available version through 1.0.2.
Risk and Exploitability
The security rating of 5.3 indicates moderate severity, and the probability of exploitation is seen as less than 1 %. The vulnerability is not documented in the KEV catalog. The likely attack vector is through the plugin’s admin interface or exposed endpoints, relying on missing authorization checks to reach protected functionality; this is inferred from the description.
OpenCVE Enrichment