Impact
A missing server‑side check in WP Express Checkout plugins prior to version 2.5.0 allows an unauthenticated user to create an order and mark it as paid without completing a payment transaction. This flaw enables attackers to acquire goods or services without paying, resulting in financial loss and potential abuse of the merchant’s payment processing system.
Affected Systems
The vulnerability affects the WordPress plugin WP Express Checkout for all versions older than 2.5.0. The vendor is listed as Unknown:WP Express Checkout; no additional version specifics are provided beyond the major release threshold.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, reflecting the business impact rather than a system compromise. The EPSS score of < 1% indicates a very low but non‑zero likelihood of exploitation, and the vulnerability is not included in the CISA KEV catalogue. The attack vector is inferred to be unauthenticated via the public web interface, as the flaw can be exploited without logging in.
OpenCVE Enrichment