Impact
The vulnerability is an unauthenticated broken access control flaw that allows an attacker to invoke privileged functions of the Autopay plugin without needing valid credentials. This flaw, classified as CWE-862, could enable the attacker to alter payment settings, create or modify orders, or otherwise compromise the payment flow, potentially leading to financial loss or unauthorized transactions.
Affected Systems
WordPress sites running the Autopay dla WooCommerce plugin by wpdesk, versions up to 2.2.27, are affected. Any installation using these versions is at risk until the plugin is updated.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score of less than 1% suggests that the likelihood of exploitation is low at present. The vulnerability is not listed in the CISA KEV catalog. Based on the description the attack vector is inferred to be unauthenticated access via exposed plugin endpoints, meaning an attacker does not need to log in to take advantage of the flaw.
OpenCVE Enrichment