Impact
The vulnerability lies in the PayPay for WooCommerce plugin versions 0.5 through 0.9.3, which fails to authenticate payment notifications before processing them. An attacker who knows the merchant identifier can forge a webhook and cause the shop to mark any chosen order as paid, or alternatively cancel or fail the order. The effect is the ability to alter order status without proper authorization, potentially leading to financial loss or service denial for legitimate customers. This weakness is a form of unchecked authentication that directly compromises payment integrity.
Affected Systems
WordPress sites using the unknown Payment Gateway PayPay for WooCommerce plugin from version 0.5 up to 0.9.3 are affected. The plugin is typically installed as a WooCommerce payment gateway, and any store using it within the vulnerable version range must verify and patch the plugin.
Risk and Exploitability
The CVSS score of 5.9 indicates a moderate severity based on ability to modify financial transactions. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known large‑scale exploitation yet. The likely attack vector is remote: an unauthenticated attacker sends a crafted webhook to the store’s PayPay endpoint, exploiting the missing verification. Because the attacker only needs to know the merchant ID, the barrier to launch an attack is low once the ID is discovered through public means.
OpenCVE Enrichment