WordPress Plugin Vulnerabilities

OpenPix <= 2.13.3 - Subscriber+ Payment Gateway Settings Reset

Description

The plugin allows any authenticated user to trigger AJAX actions that reset payment gateway configuration options without capability or nonce checks. This permits any authenticated users, such as subscribers to clear API credentials and webhook status, causing persistent disruption of OpenPix payment functionality.

Proof of Concept

Affects Plugins

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Md. Moniruzzaman Prodhan (NomanProdhan)
Submitter
Md. Moniruzzaman Prodhan (NomanProdhan)
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-01-20 (about 22 days ago)
Added
2026-01-13 (about 29 days ago)
Last Updated
2026-01-13 (about 29 days ago)

Other