Impact
The vulnerability allows an unauthenticated attacker to trigger the Rede Itaú plugin’s PIX payment webhook without verification, enabling the manipulation of an order’s status from pending to paid. This can cause the WooCommerce store to credit orders that have not been paid, resulting in revenue loss, compromised financial integrity, and increased fraud risk.
Affected Systems
The affected component is the Rede Itaú for WooCommerce – Payment PIX, Credit Card and Debit WordPress plugin prior to version 5.4.7. No specific sub‑versions are listed beyond the <5.4.7 cutoff.
Risk and Exploitability
The plugin accepts external webhook requests without authentication or signature checks, so an attacker can send an HTTP request with appropriate data to the webhook URL and change order status. Because no prior authentication is required, the vulnerability is easy to exploit. The CVSS score is 5.3, indicating moderate severity. The low EPSS score (<1%) indicates a small but non-zero exploitation probability, while it is not listed in KEV; this does not diminish the inherent risk as the impact on financial transactions is significant.
OpenCVE Enrichment