Impact
The Autopay WordPress plugin before version 5.0.1 does not verify the signature on a payment callback, allowing attackers to trigger the callback without authentication. This flaw lets unauthenticated users retrieve or delete the payment parameters stored for other customers' orders, compromising confidentiality and integrity of sensitive payment data. The weakness is a typical authorization bypass identified as CWE-863.
Affected Systems
WordPress sites running the Autopay plugin, any version older than 5.0.1. The vulnerability targets browsers or services that can make requests to the plugin's payment callback endpoint.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate risk, and the EPSS score of less than 1% suggests exploitation is unlikely at present. The vulnerability is not listed in the CISA KEV catalog. Attackers could exploit it by sending crafted HTTP requests to the callback URL, potentially creating or deleting payment parameters without needing valid credentials.
OpenCVE Enrichment