Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vm49-qx2v-g672

Опубликовано: 11 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

The Pix para Woocommerce WordPress plugin through 2.13.3 allows any authenticated user to trigger AJAX actions that reset payment gateway configuration options without capability or nonce checks. This permits any authenticated users, such as subscribers to clear API credentials and webhook status, causing persistent disruption of OpenPix payment functionality.

The Pix para Woocommerce WordPress plugin through 2.13.3 allows any authenticated user to trigger AJAX actions that reset payment gateway configuration options without capability or nonce checks. This permits any authenticated users, such as subscribers to clear API credentials and webhook status, causing persistent disruption of OpenPix payment functionality.

EPSS

Процентиль: 2%
0.00013
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 6.5
nvd
3 месяца назад

The OpenPix for WooCommerce WordPress plugin through 2.13.3 allows any authenticated user to trigger AJAX actions that reset payment gateway configuration options without capability or nonce checks. This permits any authenticated users, such as subscribers to clear API credentials and webhook status, causing persistent disruption of OpenPix payment functionality.

EPSS

Процентиль: 2%
0.00013
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-862