Impact
The zipMoney(Zip Co) Payments Plugin for WooCommerce for WordPress contains an endpoint that handles option deletion without checking the caller’s authorization or the name of the option supplied. that deletes any WordPress option, including those that enable the plugin and control critical site settings. Removing, in worst cases, render the entire WordPress site unusable. The flaw is a CWE-862 type weakness.
Affected Systems
Any WordPress installation that has the zipMoney(Zip Co) Payments Plugin for WooCommerce with a version before 2.4.0 is vulnerable. No specific operating system or WordPress core version restrictions are noted; the flaw resides purely in the plugin code.
Risk and Exploitability
The flaw carries a CVSS score of 9.1, reflecting a high impact on confidentiality, integrity, and availability. Based on the description, the likely attack vector is a direct HTTP request to the front‑end handler. The EPSS score is a low probability of exploitation at the present time. However, the vulnerability is not included in the CISA KEV catalog, so there is no evidence of widespread exploitation. Because the attack vector is a direct HTTP request to a front‑end handler, any machine that can reach the site’s public interface could exploit it if the endpoint is exposed to unauthenticated traffic.
OpenCVE Enrichment