Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8v46-f2rh-pfmp

Опубликовано: 14 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

The Aplazo Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the check_success_response() function in all versions up to, and including, 1.4.2. This makes it possible for unauthenticated attackers to set any WooCommerce order to pending payment status.

The Aplazo Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the check_success_response() function in all versions up to, and including, 1.4.2. This makes it possible for unauthenticated attackers to set any WooCommerce order to pending payment status.

EPSS

Процентиль: 21%
0.00067
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 5.3
nvd
25 дней назад

The Aplazo Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the check_success_response() function in all versions up to, and including, 1.4.2. This makes it possible for unauthenticated attackers to set any WooCommerce order to `pending payment` status.

EPSS

Процентиль: 21%
0.00067
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-862