Impact
The SUMIT Payment Gateway for WooCommerce plugin before version 4.0.0 fails to verify that a payment provider's notification is authentic before marking an order as paid. An attacker can therefore forge a payment notification and cause the system to treat a pending order as paid, granting access to paid content or services without completing payment. This flaw allows attackers to manipulate order status without authorization, exploiting a weakness in access control.
Affected Systems
WordPress sites that have installed the SUMIT Payment Gateway for WooCommerce plugin and are running any version prior to 4.0.0. The vendor is not identified in the public references, but the vulnerability is specific to this plugin used within WooCommerce.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, and the EPSS score is not available, so the estimated exploitation probability cannot be quantified. The vulnerability is listed as not being in the CISA KEV catalog. Attackers can exploit the flaw remotely by sending a forged IPN request over the network to the plugin’s notification endpoint, with no authentication required. While no public exploitation has been reported, the fact that the issue can be triggered by any unauthenticated user raises concern for sites with active payment gateways.
OpenCVE Enrichment