Impact
An unauthenticated broken access control flaw exists in the Conekta Payment Gateway WordPress plugin prior to version 6.2.5, allowing an attacker that can reach the plugin’s administration endpoints to modify payment gateway configuration or initiate payment operations without authentication. If exploited, the attacker could misconfigure payment parameters, redirect funds, or interfere with transaction processing, leading to financial loss or service disruption. The weakness is a classic authorization bypass (CWE‑862).
Affected Systems
WordPress sites using the Conekta Payment Gateway plugin version 6.2.4 or earlier are affected. The plugin is authored by the Conekta Group under the Conekta Payment Gateway brand.
Risk and Exploitability
The CVSS base score is 6.5, indicating a moderate impact that may compromise confidentiality and integrity of payment data. The EPSS score is unavailable, but no public exploits or KEV listing exist, suggesting no widespread active exploitation. The vulnerability requires no special privileges and can be triggered via standard web requests to the plugin’s admin interface, making it likely susceptible to remote exploitation from any network that can reach the WordPress installation.
OpenCVE Enrichment