Impact
The Razorpay Payment Links for WooCommerce plugin contains a missing authorization check that permits users without proper privileges to access or alter payment link configurations. This flaw is classified as improper authorization (CWE-862) and could lead to unauthorized changes to transaction settings or exposure of sensitive financial data.
Affected Systems
WordPress installations that use the knitpay Razorpay Payment Links for WooCommerce plugin version 2.1.4 or earlier are affected. Any site running a vulnerable version and not updated beyond 2.1.4 is susceptible, regardless of other WordPress configuration.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity impact on confidentiality, integrity, and availability. The EPSS score, being less than 1%, suggests a very low likelihood of exploitation under current conditions, and the vulnerability is not listed in the CISA KEV catalog. Attackers would likely need access to a user account with elevated privileges or exploit a misconfigured role to leverage this broken access control. In the absence of such conditions, the risk remains largely theoretical, yet the potential damage warrants prompt attention.
OpenCVE Enrichment