Back to overview

CVE-2026-12972

MEDIUM Exploitation: PoC
5.3
CVSS 3.1
Description
The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to tamper with the payment-related metadata of arbitrary WooCommerce orders.

Metadata

CVE ID
CVE-2026-12972
State
PUBLISHED
Assigner
WPScan
Reserved
2026-06-23 09:47 UTC
Published
2026-07-20 06:00 UTC
Last updated
2026-07-20 15:00 UTC
Primary CWE
CWE-284
CWE-284 Improper Access Control
Vendor / Product
Unknown / PayPlus Payment Gateway
Sources
cve.org  ·  NVD

Severity & Metrics

5.3 MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
yes
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
Unknown PayPlus Payment Gateway 0 < 8.2.2
Weakness (CWE)
CWESourceDescription
cna CWE-284 Improper Access Control
CWE-284 adp CWE-284 Improper Access Control
CVSS scores (1)
ScoreSeverityVersionSourceVector
5.3 MEDIUM 3.1 adp CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Back to overview