Impact
The Deema Payment Gateway plugin for WordPress through version 1.1.2 does not verify the authenticity of payment provider notifications, and the plugin’s verification feature is disabled by default. This flaw allows an attacker who can send requests to the webhook endpoint to mark an unpaid order as paid, cancel an order, or trigger a refund, effectively manipulating transactional data without authentication. The vulnerability is a classic example of missing authentication for critical operations and improper access control, enabling attackers to alter financial records and potentially recover funds they are not entitled to.
Affected Systems
The only affected product is the Deema Payment Gateway WordPress plugin, with all versions up to and including 1.1.2 vulnerable. No specific operating system or platform constraints are mentioned beyond its use as a WordPress plugin.
Risk and Exploitability
This flaw exposes a high-impact exploitation path that an attacker can reach over the public internet by crafting a webhook payload. The lack of a public EPSS score means the exploitation probability is unknown, but the absence of any KEV listing does not diminish the seriousness for organizations using the plugin. Because an attacker can perform the attack without any prior authentication or privileged access, the risk is considered high.
OpenCVE Enrichment