Impact
The vulnerability is an unauthenticated Insecure Direct Object Reference that allows attackers to retrieve or modify data by manipulating identifiers, potentially exposing order or payment records and compromising confidentiality and integrity; it is categorized as CWE‑639.
Affected Systems
WordPress sites using the Razorpay for WooCommerce plugin version 4.8.7 or earlier are affected; the plugin is developed by Razorpay, and the flaw exists in all versions up to and including 4.8.7.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate risk, and while the EPSS score is not available, the lack of a KEV listing suggests no widespread exploitation has been observed; attackers could exploit the vulnerability remotely without authentication, potentially accessing sensitive order data if the plugin does not properly validate object identifiers.
OpenCVE Enrichment