Impact
An unauthenticated broken access control flaw exists in the WordPress PayPlus Payment Gateway plugin versions 8.2.5 and earlier. The vulnerability allows a victimless user to interact with privileged plugin endpoints without authentication, potentially enabling unauthorized configuration changes or exposure of payment-related data. The weakness corresponds to CWE-862, which denotes improper access control.
Affected Systems
The affected product is the PayPlus Payment Gateway plugin for WordPress, as distributed by the PayPlus Tech Team. All releases up to and including version 8.2.5 are vulnerable.
Risk and Exploitability
The CVSS base score of 6.5 places this flaw in the medium severity range. No EPSS score is currently available, and it is not listed in CISA’s KEV catalog. Inferred from the description, the attack surface is the web interface of the WordPress site, where a remote attacker can exploit the plugin’s exposed endpoints with unauthenticated HTTP requests. No special privileges or configuration are required, making the vulnerability highly actionable.
OpenCVE Enrichment