Impact
The PayU India WordPress plugin up to version 3.8.9 contains an unauthenticated broken access control flaw that can be exploited by sending crafted requests without authentication. This weakness allows the attacker to access privileged actions that should be restricted to authorized users, potentially exposing sensitive financial data or allowing configuration changes. The flaw maps to CWE‑862, indicating a lack of proper authorization checks.
Affected Systems
WordPress installations that have the PayU India plugin version 3.8.9 or earlier. These sites may have the admin or payment processing endpoints exposed through the plugin, enabling an attacker to target the vulnerable functionality.
Risk and Exploitability
The CVSS score of 7.5 classifies the issue as high severity. The EPSS score below 1% implies a low probability of widespread exploitation at present, and the vulnerability is not listed in the CISA KEV catalog, reducing immediate threat visibility. However, the attack vector is likely remote with no authentication required, meaning that any visitor to the affected WordPress site could potentially trigger the flaw. Because the vulnerability is a pure access control issue, successful exploitation would grant the attacker unauthorized administrative access, exposing confidential transaction data and allowing possible manipulation of payment settings.
OpenCVE Enrichment