Impact
The Verge3D WordPress plugin, between versions 4.1.0 and 4.13.0, omits a crucial verification step with its payment gateway and does not confirm that an order belongs to the user initiating the request, allowing an unauthenticated request to the v3d_payment_done endpoint to mark any order as paid. This flaw is a form of authorization bypass, enabling attackers to receive paid content or services without completing the legitimate payment process. The lack of proper validation permits compromise of the monetary integrity of the site, potential loss of revenue, and breach of trust with customers.
Affected Systems
The affected system is the Verge3D WordPress plugin, used by Verge3D Publishing and E-Commerce. All installations of the plugin from release 4.1.0 through 4.13.0 are vulnerable, regardless of host WordPress configuration. No specific CPE string is provided, but the scope includes all sites running these plugin versions.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, suggesting that there may be limited public exploitation data. However, the public nature of the plugin and the fact that the payment confirmation endpoint can be reached without authentication indicate a likely web‑based attack vector. An attacker with shallow technical skills could craft a request to the vulnerable endpoint, bypass payment verification, and gain access to paid content or services.
OpenCVE Enrichment