Impact
The Xendit Payment WordPress plugin versions 7.1.0 and earlier contain an unauthenticated broken access control flaw that allows attackers to perform privileged operations or view sensitive data. The weakness follows CWE-862 and can result in unauthorized exposure of payment information or manipulation of configuration settings, compromising confidentiality and integrity of transaction data.
Affected Systems
WordPress sites that utilize the Xendit Payment plugin at or below version 7.1.0. The plugin provides integration with the Xendit payment gateway for WordPress, making it a target for sites that have installed it.
Risk and Exploitability
The CVSS score of 7.5 classifies the issue as high severity. The EPSS score of <1% indicates a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog, implying no publicly known exploitation. The likely attack vector emerges from unauthenticated HTTP requests to the plugin’s endpoints that are not protected by proper authentication checks.
OpenCVE Enrichment