Impact
The vulnerability is a broken access control flaw in the Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) plugin, affecting all versions up to 1.0.7. It allows unauthenticated users to bypass normal authorization checks and potentially carry out privileged operations within the payment gateway. The flaw is classified as CWE‑862, indicating missing authorization checks that can lead to unauthorized manipulation of payment processes.
Affected Systems
The affected product is the WoompaLoompa Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) plugin. All installations of version 1.0.7 or earlier are vulnerable; no other products or versions are listed as affected.
Risk and Exploitability
This vulnerability carries a CVSS score of 7.5 and is not listed in the CISA KEV catalog, indicating it is a high‑severity issue but not a known widespread exploitation in the wild. The exploitation vector is likely web‑based and requires only unauthenticated access to the site where the plugin is installed. Attackers can exploit this weakness by sending crafted requests to privileged endpoints exposed by the plugin, potentially manipulating payment transactions or accessing sensitive transaction data.
OpenCVE Enrichment