Description
Missing Authorization vulnerability in codemstory 워드프레스 결제 심플페이 pgall-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 워드프레스 결제 심플페이: from n/a through 5.5.17.
Published: 2026-10-09
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized configuration change
Action: Apply patch
AI Analysis

Impact

The vendor provides a WordPress payment plugin, and the vulnerability is a missing authorization flaw that enables an attacker to modify configuration settings within the plugin. The flaw stems from incorrectly configured access control security levels, meaning that users with insufficient privileges can submit configuration changes that the system accepts. This can lead to unauthorized alterations of payment handling behaviors, potentially impacting transaction routing, fee calculations, or security settings.

Affected Systems

The affected product is the codemstory WordPress payment plugin (pgall-for-woocommerce), versions up to and including 5.5.17. No specific sub‑versions are listed beyond the upper bound; the issue is present in any installation using those releases.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity. EPSS is not available, but the absence from the KEV catalog suggests that no large‑scale exploitation has been observed yet. Based on the description the attack vector is web‑based; an attacker can exploit the flaw by sending malformed requests to the plugin’s administrative endpoints. No additional privileges are required beyond standard user rights if the access controls are misconfigured, so the likelihood of exploitation depends on whether the site’s authentication and role settings have been properly configured.

Generated by OpenCVE AI on October 9, 2026 at 11:46 UTC.

Remediation

Vendor Solution

Update the WordPress 워드프레스 결제 심플페이 plugin to the latest available version (at least 5.5.18).


OpenCVE Recommended Actions

  • Update the WordPress payment plugin to the latest version (at least 5.5.18) as soon as possible.
  • If an update cannot be performed immediately, restrict access to the plugin’s administrative interface by applying role‑based permissions or using a web application firewall rule to block unauthorized configuration changes.
  • Verify that only users with the "Administrator" role can reach the settings page and that other roles cannot alter settings.
  • After applying the update or restrictions, monitor the plugin’s configuration files and admin logs for any unexpected changes.

Generated by OpenCVE AI on October 9, 2026 at 11:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 10:15:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in codemstory 워드프레스 결제 심플페이 pgall-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 워드프레스 결제 심플페이: from n/a through 5.5.17.
Title WordPress 워드프레스 결제 심플페이 plugin <= 5.5.17 - Settings Change vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-09T10:00:19.713Z

Reserved: 2026-09-22T09:18:20.379Z

Link: CVE-2026-95597

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-09T10:16:42.510

Modified: 2026-10-09T13:20:48.273

Link: CVE-2026-95597

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T12:00:07Z

Weaknesses