Impact
The flaw arises because the plugin does not enforce a capability check on several admin AJAX endpoints that control its payment‑gateway configuration. Contributors can therefore invoke these actions to delete, wipe, or alter the configuration stored by the plugin, which includes payment credentials. The result is that an attacker with only contributor access can modify or erase payment settings, potentially exposing sensitive data or disrupting commerce operations.
Affected Systems
WordPress sites running the Paymob for WooCommerce plugin version earlier than 4.1.14 are affected. The vulnerability affects any installation of the plugin before that version, regardless of additional plugins or themes.
Risk and Exploitability
The CVSS score of 4.7 indicates moderate severity. The EPSS probability is below 1 % and the vulnerability is not listed in CISA KEV. An attacker would need authenticated access with the WordPress contributor role and must send crafted AJAX requests to the plugin’s endpoints. Because the attack requires legitimate credentials and a specific role, the likelihood of exploitation is low, but the impact on financial data warrants attention.
OpenCVE Enrichment