Impact
The vendor provides a WordPress payment plugin, and the vulnerability is a missing authorization flaw that enables an attacker to modify configuration settings within the plugin. The flaw stems from incorrectly configured access control security levels, meaning that users with insufficient privileges can submit configuration changes that the system accepts. This can lead to unauthorized alterations of payment handling behaviors, potentially impacting transaction routing, fee calculations, or security settings.
Affected Systems
The affected product is the codemstory WordPress payment plugin (pgall-for-woocommerce), versions up to and including 5.5.17. No specific sub‑versions are listed beyond the upper bound; the issue is present in any installation using those releases.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. EPSS is not available, but the absence from the KEV catalog suggests that no large‑scale exploitation has been observed yet. Based on the description the attack vector is web‑based; an attacker can exploit the flaw by sending malformed requests to the plugin’s administrative endpoints. No additional privileges are required beyond standard user rights if the access controls are misconfigured, so the likelihood of exploitation depends on whether the site’s authentication and role settings have been properly configured.
OpenCVE Enrichment