Impact
Unauthenticated Cross Site Request Forgery (CSRF) in the Razorpay Payment Links for WooCommerce plugin allows an attacker to craft a malicious web request that a logged‑in user will unknowingly submit. The flaw exists for versions 2.1.5 and earlier and is identified as CWE‑352, indicating a weakness in the protection against forged requests. Because the attacker does not need to obtain credentials, the vulnerability can lead to the creation of unauthorized payment links, modification of existing links, or other unintended changes that could result in financial loss or service disruption for site owners.
Affected Systems
The vulnerability affects installations of the Razorpay Payment Links for WooCommerce plugin provided by KnitPay, specifically versions 2.1.5 and all prior releases. It is inferred that any WordPress site that has installed this plugin and has an exposed user interface for payment link management is at risk.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, and the EPSS score is not available, suggesting limited data on active exploitation but still highlighting potential risk. The vulnerability is not listed in CISA KEV. Attackers can exploit the flaw by sending a crafted request that bypasses CSRF validation; based on the description, it is inferred that such a request would typically be delivered through a malicious web page or email link that the victim visits while logged into the site. Successful exploitation would require the victim to be authenticated to the WordPress administration area; this requirement is inferred.
OpenCVE Enrichment