Impact
The vulnerability lies in the PayPay for WooCommerce plugin versions 0.5 through 0.9.3, which fails to authenticate payment notifications before processing them. An attacker who knows the merchant identifier can forge a webhook and cause the shop to mark any chosen order as paid, or alternatively cancel or fail the order. The effect is the ability to alter order status without proper authorization, potentially leading to financial loss or service denial for legitimate customers directly compromises payment integrity.
Affected Systems
WordPress sites using the unknown Payment Gateway PayPay for WooCommerce plugin from version 0.5 up to 0.9.3 are affected. The plugin is typically installed as a WooCommerce payment gateway, and any store using it within the vulnerable version range must verify and patch the plugin.
Risk and Exploitability
The CVSS score of 5.9 indicates a moderate severity based on the ability to modify financial transactions. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, which suggests there are no known large‑scale exploitations yet. The exploit requires an attacker to send a crafted webhook to the store’s PayPay endpoint, taking advantage of the missing verification. Because the attacker only needs to know the merchant ID, the barrier to launch an attack is low; however, the information on how the merchant ID is obtained is not present in the data, so the claim that it is discovered through public means is inferred rather than explicitly stated.
OpenCVE Enrichment