Impact
Unauthenticated Broken Access Control in Paymob for WooCommerce plugins up to version 4.1.2 allows an attacker without authentication to invoke privileged actions that are intended for authorized administrators. This flaw can enable manipulation of payment processing settings, potentially exposing sensitive financial data or facilitating unauthorized transactions. The weakness is classified as CWE‑862, indicating improper authorization controls.
Affected Systems
The vulnerability affects the Paymob for WooCommerce plugin for WordPress, specifically versions 4.1.2 and earlier. Systems running these versions are susceptible; any WordPress site that has not upgraded beyond 4.1.2 should be considered vulnerable.
Risk and Exploitability
The CVSS score of 7.5 signifies a high severity. With no EPSS data, the likelihood of exploitation in the near term remains unclear, but the absence from CISA KEV suggests no known widespread active exploitation. An attacker would likely target exposed HTTP endpoints that the plugin registers, sending crafted requests that bypass authentication checks. Successful exploitation would grant the attacker the same permissions as the plugin’s administrative interface.
OpenCVE Enrichment