Impact
The Peach Payments Gateway plugin contains a missing authorization check that enables users without the required permissions to access endpoints that should be protected. This flaw is a missing authorization weak point (CWE-862). The specific actions an attacker could perform are not explicitly documented in the CVE record, but any unauthorized access to protected plugin functionality could potentially expose or alter sensitive payment information.
Affected Systems
The vulnerability affects the WordPress Peach Payments Gateway plugin for all releases from the earliest available version up to and including 4.0.2. Any WordPress site that has installed Peach Payments Gateway with a version <= 4.0.2 is potentially impacted. Administrators should verify the installed plugin version and, if necessary, update the plugin.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity vulnerability, and the EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely exploitation path involves sending crafted HTTP requests to plugin endpoints that should enforce proper authorization but do not, potentially allowing an attacker to access restricted plugin functionality.
OpenCVE Enrichment