Sceawere
Vulnerability Detail
CVE-2026-32578UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
ECPay WooCommerce Broken Access Control
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 16h ago
- Vendor
- techsupport
- Product
- ECPay Ecommerce for WooCommerce
- Attack Type
- CWE-862 Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Subscriber Broken Access Control in ECPay Ecommerce for WooCommerce <= 1.1.2606090 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-10-06T09:17:43.460Z",
"pubdate": "2026-10-06T09:17:43.460Z",
"executiveSummary": "A critical broken access control vulnerability exists in the ECPay Ecommerce for WooCommerce plugin in versions 1.1.2606090 and earlier.\nThis vulnerability allows authenticated users with subscriber-level privileges to perform unauthorized actions due to improper authorization checks within the plugin's administrative or restricted functions.\nThe vulnerability effectively bypasses the Principle of Least Privilege, enabling unauthorized users to invoke sensitive methods that are typically reserved for administrators or higher-privileged roles.\nRisk implications include potential unauthorized configuration changes, data exposure, or manipulation of payment-related settings within the WooCommerce environment.\nExploitation requires the attacker to possess an active subscriber account on the target WordPress installation.\nThe flaw stems from insufficient validation of user capabilities during the execution of request handlers, allowing an attacker to craft requests that the system improperly treats as legitimate administrative commands.",
"technicalDetails": "The vulnerability originates from a failure to implement robust capability checks (e.g., current_user_can()) on sensitive administrative endpoints or AJAX/REST API handlers within the ECPay Ecommerce for WooCommerce plugin.\nIn the affected versions (<= 1.1.2606090), the plugin code exposes specific functional handlers that fail to verify if the requesting user possesses 'manage_options' or equivalent administrative permissions before processing the request.\nWhen an authenticated subscriber sends a crafted request to these vulnerable endpoints, the application's backend processes the request under the assumption that the caller has already been validated for administrative access. This bypasses the intended security boundary enforced by the WordPress user role system.\nThe attack flow typically involves the following steps: First, the attacker authenticates as a standard subscriber on the target site. Second, the attacker identifies the specific URL or API endpoint associated with the ECPay plugin functionality that lacks authorization logic. Third, the attacker crafts a malicious request (often via POST or GET) targeting these functions, potentially including parameters intended to modify plugin configurations, trigger internal processes, or access restricted data fields.\nBecause the plugin lacks the necessary permission checks within its controller logic, the server executes the requested operations on behalf of the subscriber. The network exposure is limited to the web server's front-facing interface, as the attack is performed via standard HTTP(S) requests.\nPost-exploitation impact varies depending on the specific administrative functions exposed by the plugin. An attacker could potentially reconfigure payment gateway settings, intercept transaction data, or manipulate the plugin's interaction with the ECPay gateway, leading to site-wide disruption, financial misdirection, or unauthorized data access.\nThe root cause is definitively attributed to improper access control (CWE-285/CWE-862) wherein authorization logic is either completely absent or incorrectly implemented in the plugin's request handling hooks. This allows for lateral privilege escalation within the context of the plugin's specific capabilities."
}