Impact
This vulnerability resides in the Flutterwave WooCommerce payment gateway plugin for WordPress, affecting all releases up to and including 3.3.0. It is a classic example of broken authentication, where a remote actor can authenticate into the system without possessing valid credentials. The flaw allows an attacker to gain privileged access to the WooCommerce administration interface, potentially modifying orders, intercepting or manipulating payments, or altering sensitive configuration settings. The weaknesses responsible for this are categorized under CWE‑288, indicating failures in authentication controls.
Affected Systems
Vendors: Flutterwave; Product: Flutterwave WooCommerce plugin for WordPress. Version range: any release 3.3.0 or earlier. No other vendors are listed as affected.
Risk and Exploitability
The CVSS base score of 6.5 signals a medium severity issue. The EPSS score is currently not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw remotely without authentication, likely by crafting HTTP requests to the plugin’s administration endpoints and leveraging missing credential checks. The likely attack vector is inferred from the description as sending crafted HTTP requests to such endpoints. Because the flaw is unauthenticated, it carries a high potential for abuse, but the lack of a publicly confirmed exploitation or a known active exploit reduces the immediate risk. System administrators should treat the vulnerability as moderate to high risk and prioritize remediation.
OpenCVE Enrichment