Description
Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) <= 1.0.7 versions.
Published: 2026-08-13
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a broken access control flaw in the Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) plugin, affecting all versions up to 1.0.7. It allows unauthenticated users to bypass normal authorization checks and potentially carry out privileged operations within the payment gateway. The flaw is classified as CWE‑862, indicating missing authorization checks that can lead to unauthorized manipulation of payment processes.

Affected Systems

The affected product is the WoompaLoompa Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) plugin. All installations of version 1.0.7 or earlier are vulnerable; no other products or versions are listed as affected.

Risk and Exploitability

This vulnerability carries a CVSS score of 7.5 and is not listed in the CISA KEV catalog, indicating it is a high‑severity issue but not a known widespread exploitation in the wild. The exploitation vector is likely web‑based and requires only unauthenticated access to the site where the plugin is installed. Attackers can exploit this weakness by sending crafted requests to privileged endpoints exposed by the plugin, potentially manipulating payment transactions or accessing sensitive transaction data.

Generated by OpenCVE AI on August 13, 2026 at 15:49 UTC.

Remediation

Vendor Solution

Update the WordPress Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) Plugin to the latest available version (at least 1.0.8).


OpenCVE Recommended Actions

  • Upgrade the Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) plugin to version 1.0.8 or newer.
  • If an upgrade is not possible, remove the plugin from the WordPress installation to eliminate the exposure.
  • If removal is not feasible, apply network or application layer restrictions, such as IP whitelisting or firewall rules, to block unauthenticated access to the plugin’s administrative endpoints.

Generated by OpenCVE AI on August 13, 2026 at 15:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) <= 1.0.7 versions.
Title WordPress Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) plugin <= 1.0.7 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-13T15:16:42.357Z

Reserved: 2026-07-27T09:00:08.213Z

Link: CVE-2026-66431

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T14:17:05.120

Modified: 2026-08-13T16:18:42.807

Link: CVE-2026-66431

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T16:00:11Z

Weaknesses