Impact
The vulnerability is an unauthenticated broken access control flaw in the WordPress Payment Gateway for PayPal on WooCommerce plugin up to version 9.1.4. Based on the description, it is inferred that this flaw enables an unauthenticated user to access privileged areas of the plugin, potentially leading to unauthorized configuration changes or data exposure. The weakness corresponds to CWE-862.
Affected Systems
The affected product is Easy Payment: Payment Gateway for PayPal on WooCommerce. Versions 9.1.4 and earlier are vulnerable.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, while the EPSS score of less than 1% shows that exploitation activity is currently very low. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector is web-based, requiring unauthenticated access to the plugin’s interface.
OpenCVE Enrichment