Impact
The ePayco Payment Gateway for WooCommerce plugin does not validate the authenticity of payment confirmation requests. As a result an attacker can mark customer orders as paid without any valid gateway signature. The flaw is an authentication bypass, identified as CWE‑345, and can lead to fraudulent order fulfillment and potential monetary loss.
Affected Systems
Any WordPress website that installs the ePayco Payment Gateway for WooCommerce plugin with a version earlier than 8.4.7 is vulnerable. The vendor for this plugin is listed only as ePayco Payment Gateway for WooCommerce, and no further version enumeration is provided beyond the “< 8.4.7” threshold.
Risk and Exploitability
The CVSS score of 5.3 places this vulnerability at moderate severity. The EPSS score of less than 1% indicates a very low probability of exploitation. It is not listed in the CISA KEV catalog. According to the description it is inferred that attackers can remotely trigger the flaw by sending crafted HTTP requests to the payment confirmation endpoint, thereby bypassing all authentication checks.
OpenCVE Enrichment