Impact
The Simple Payment plugin for WordPress versions 2.5.2 or earlier contains an unauthenticated broken access control flaw that permits attackers to bypass authentication checks and access privileged functions or modify payment settings. This vulnerability allows unauthenticated users to potentially alter configuration values, view sensitive data, or manipulate transaction processing without authorization. No exploitation or confirmation of data disclosure is provided in the current description, but the lack of authentication checks creates a vector for privilege escalation within the plugin ecosystem.
Affected Systems
The vulnerability affects the WordPress Simple Payment plugin made by yalla ya! in versions up to and including 2.5.2. WordPress site administrators with this plugin installed and not updated to at least 2.5.3 are exposed.
Risk and Exploitability
The CVSS score of 7.5 indicates high potential impact if exploited. The EPSS score is not available, so the likelihood of exploitation in the wild cannot be quantified from this data. The vulnerability is not listed in the CISA KEV catalog. Attackers can reach the exposed administrative endpoints over the web without credentials, so any user with access to the site can exploit the flaw. Until the plugin is updated, the risk is moderate to high for unsophisticated attackers.
OpenCVE Enrichment