Impact
Unsecured authentication mechanisms in the Piraeus Bank WooCommerce Payment Gateway plugin allow an attacker to authenticate without valid credentials. This flaw can enable the attacker to perform actions reserved for legitimate users, such as initiating or modifying payment transactions, potentially leading to financial compromise or unauthorized changes to merchant data.
Affected Systems
The vulnerability affects the WordPress plugin "Piraeus Bank WooCommerce Payment Gateway" version 3.2.0 distributed by Papaki (Enartia S.A.). No other vendor or product versions are identified as impacted.
Risk and Exploitability
The flaw has a CVSS score of 6.5, indicating a moderate severity. At this time an EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog. The most probable attack vector is via the WordPress web interface, targeting the plugin's authentication endpoints. An attacker only needs network access to the affected site and can craft requests to exploit the authentication bypass without additional prerequisites.
OpenCVE Enrichment