Impact
Unauthenticated bypass within the WP EasyPay plugin allows an attacker to gain restricted access without credentials, potentially enabling manipulation of payment settings or transaction data. The vulnerability enables privilege escalation within the plugin’s protected functions, as indicated by CWE-472. This could compromise the integrity of payment workflows on a WordPress site.
Affected Systems
WordPress sites running the WP EasyPay plugin by Saad Iqbal, versions 4.5.3 and below, are affected. Only these versions are vulnerable; newer releases such as 4.5.4 contain the fix.
Risk and Exploitability
The vulnerability has a CVSS score of 5.3, indicating a moderate severity. EPSS data is not available, and the flaw is not listed in CISA’s KEV catalog. The attack vector is inferred to be via the web, as the bypass can be triggered without authentication if the vulnerable plugin is exposed to the public. Given the moderate score, the likelihood of exploitation remains uncertain but should still be mitigated promptly.
OpenCVE Enrichment