WordPress Plugin Vulnerabilities

PayPlus Payment Gateway < 8.2.2 - Unauthenticated Order Payment Metadata Tampering

Description

The plugin does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to tamper with the payment-related metadata of arbitrary WooCommerce orders.

Proof of Concept

Affects Plugins

References

Classification

Type
ACCESS CONTROLS
CWE

Miscellaneous

Original Researcher
Pedro Pinho
Submitter
Pedro Pinho
Verified
Yes

Timeline

Publicly Published
2026-06-29 (about 22 days ago)
Added
2026-06-29 (about 21 days ago)
Last Updated
2026-06-29 (about 21 days ago)

Other