Description
Missing Authorization vulnerability in peachpayments Peach Payments Gateway wc-peach-payments-gateway allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Peach Payments Gateway: from n/a through <= 4.0.2.
Published: 2026-07-13
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Peach Payments Gateway plugin contains a missing authorization check that enables users without the required permissions to access endpoints that should be protected. This flaw is a missing authorization weak point (CWE-862). The specific actions an attacker could perform are not explicitly documented in the CVE record, but any unauthorized access to protected plugin functionality could potentially expose or alter sensitive payment information.

Affected Systems

The vulnerability affects the WordPress Peach Payments Gateway plugin for all releases from the earliest available version up to and including 4.0.2. Any WordPress site that has installed Peach Payments Gateway with a version <= 4.0.2 is potentially impacted. Administrators should verify the installed plugin version and, if necessary, update the plugin.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity vulnerability, and the EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely exploitation path involves sending crafted HTTP requests to plugin endpoints that should enforce proper authorization but do not, potentially allowing an attacker to access restricted plugin functionality.

Generated by OpenCVE AI on July 31, 2026 at 11:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Peach Payments Gateway plugin to a version newer than 4.0.2, which removes the missing authorization flaw.
  • Re‑review the plugin’s configuration to ensure that only users with the appropriate capabilities can execute payment‑related actions.
  • Implement or verify that your site’s role‑based access controls enforce proper permissions on all plugin endpoints, particularly those that handle payment data.

Generated by OpenCVE AI on July 31, 2026 at 11:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Peachpayments
Peachpayments peach Payments Gateway
Wordpress
Wordpress wordpress
Vendors & Products Peachpayments
Peachpayments peach Payments Gateway
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in peachpayments Peach Payments Gateway wc-peach-payments-gateway allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Peach Payments Gateway: from n/a through <= 4.0.2.
Title WordPress Peach Payments Gateway plugin <= 4.0.2 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Peachpayments Peach Payments Gateway
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T16:07:52.507Z

Reserved: 2026-06-24T12:46:27.805Z

Link: CVE-2026-57408

cve-icon Vulnrichment

Updated: 2026-07-13T16:02:22.840Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T12:00:05Z

Weaknesses