WordPress Plugin Vulnerabilities
PayPlus Payment Gateway < 8.2.2 - Unauthenticated Order Key Disclosure and Order Status Modification
Description
The plugin does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to disclose the secret order key of arbitrary WooCommerce orders and, under some configurations, to modify order statuses.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
NO AUTHORISATION
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
kevin(@OPCIA)
Submitter
kevin(@OPCIA)
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-06-29 (about 1 month ago)
Added
2026-06-29 (about 1 month ago)
Last Updated
2026-06-29 (about 1 month ago)