Impact
The vulnerability is an Insecure Direct Object Reference flaw in the Payment Plugins for PayPal WooCommerce WordPress plugin prior to version 2.0.26. Because the plugin does not verify that a stored payment method belongs to the user attaching it, an authenticated user can bind another customer's stored card to their own account. Once bound, the attacker may charge the account or delete the payment method, resulting in unauthorized financial activity and privacy exposure. The weakness is represented by CWE‑863 as a failure to enforce identity and authorization checks.
Affected Systems
Affected systems include any WordPress installation that has the Payment Plugins for PayPal WooCommerce plugin installed with a version earlier than 2.0.26. The vendor’s product is distributed as a plugin for WordPress and does not impose additional server or hosting requirements; any site hosting the plugin is potentially vulnerable.
Risk and Exploitability
Exploitation requires an authenticated session and the attacker’s prior knowledge of the victim’s payment provider identifier, which the plugin does not expose by default. Since the flaw is limited to authenticated users, the likely attack vector is through legitimate user accounts with permissions such as subscriber. The CVSS score of 5.9 reflects moderate impact, and the EPSS score of < 1% indicates a low but nonzero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Overall risk remains significant for sites that have not applied the latest patch or implemented stricter role controls.
OpenCVE Enrichment