Impact
CorvusPay WooCommerce Payment Gateway for WordPress omits proper authorization checks, allowing an unauthenticated attacker to send a request to the REST endpoint "/wp-json/corvuspay/cancel/" with any "order_number" value. The plugin then cancels that order, which can result in loss of revenue and damage to customer trust. The flaw is a classic authorization bypass, classified as CWE‑862.
Affected Systems
WordPress sites that use the CorvusPay WooCommerce Payment Gateway plugin version 2.7.4 or earlier are affected. All installations where the plugin is active are vulnerable regardless of user role, and the vendor is corvusinfo.
Risk and Exploitability
With a CVSS score of 5.3, the vulnerability poses a medium impact. Because the attack requires only a crafted HTTP request and no authentication, exploitation is possible, but the EPSS score indicates a very low exploitation probability (<1%). The vulnerability is not listed but the possibility of financial loss and customer disruption makes immediate action advisable.
OpenCVE Enrichment