Impact
The vulnerability in the WordPress Yookassa for WooCommerce plugin versions up to 2.16.1 is a Broken Access Control flaw (CWE‑862) that allows a malicious actor to bypass legitimate authorization checks and perform actions beyond their privilege level.
Affected Systems
WordPress sites that have the Yookassa for WooCommerce plugin version 2.16.1 or earlier installed are affected. The plugin is provided by the vendor Yoomoney.
Risk and Exploitability
The CVSS base score of 4.3 indicates moderate severity, while the EPSS score of less than 1% shows a very low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. The most likely attack vector involves direct interaction with the WordPress site, where an attacker can craft requests that exploit the missing authorization checks.
OpenCVE Enrichment