Impact
Missing authorization controls in SePay Gateway allow an unauthenticated or insufficiently privileged user to retrieve embedded sensitive data. The flaw permits an attacker to read data that should be protected, potentially exposing credentials, configuration details, or payment information stored by the plugin. The issue is identified as a CWE‑862 weakness, underscoring the lack of proper access checks.
Affected Systems
WordPress SePay Gateway plugin by SePay team, versions up to and including 1.1.20, are affected. The vulnerability persists from the initial release through version 1.1.20, with no known exceptions to this range.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity for this vulnerability. EPSS is not available, so the calculated likelihood of exploitation is uncertain, and the CISA KEV list does not currently include this issue. The likely attack vector is remote, accessed via standard HTTP(S) requests to the plugin’s endpoints. An attacker who can reach the site can construct requests that bypass authorization and read the exposed data, without the need for elevated privileges on the WordPress installation.
OpenCVE Enrichment