Sceawere
Vulnerability Detail
CVE-2026-39751UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated Broken Access Control
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 16h ago
- Vendor
- Payplug
- Product
- PayPlug for WooCommerce (Official)
- Attack Type
- CWE-862 Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Broken Access Control in PayPlug for WooCommerce (Official) <= 3.1.0 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-10-06T09:17:46.640Z",
"pubdate": "2026-10-06T09:17:46.640Z",
"executiveSummary": "The PayPlug for WooCommerce (Official) plugin, specifically versions 3.1.0 and earlier, contains a critical vulnerability categorized as Broken Access Control.\nThis flaw allows unauthenticated remote attackers to bypass authorization checks within the plugin's ecosystem.\nThe vulnerability resides in the improper implementation of access control mechanisms, which fail to validate the identity or permissions of an entity requesting sensitive operations or data.\nSuccessful exploitation permits unauthorized access to plugin functionality, potentially leading to unauthorized data exposure, manipulation of transaction settings, or unauthorized modifications to payment processing workflows.\nBecause the vulnerability is exploitable without any level of prior authentication, the risk to the underlying e-commerce environment is high.\nAttackers can leverage this flaw by sending crafted requests to the exposed endpoint, circumventing the intended security posture of the WooCommerce installation.\nImmediate remediation is necessary to prevent potential exploitation of payment configurations and ensure the integrity of the plugin operations.",
"technicalDetails": "The vulnerability is rooted in an improper authorization check within the PayPlug for WooCommerce (Official) codebase, specifically affecting versions 3.1.0 and below.\nThe flaw manifests when the plugin fails to verify the session or privilege level of an incoming request before executing administrative or privileged actions associated with the payment gateway settings.\nIn a standard WordPress/WooCommerce architecture, administrative actions must be protected by internal nonces or capability checks, such as 'manage_woocommerce' or 'manage_options', to ensure that only authorized administrators can interact with sensitive plugin endpoints.\nIn the affected versions, the plugin logic fails to enforce these checks, effectively exposing an internal API endpoint or AJAX action to the public web.\nThe attack flow begins with the attacker identifying the specific vulnerable endpoint associated with the PayPlug plugin. Once identified, the attacker crafts an HTTP GET or POST request directed toward this endpoint.\nBecause the server-side code responsible for handling the request neglects to validate the user's authentication token or permission level, the application proceeds to execute the requested logic.\nThe impact is significant, as an unauthenticated attacker could potentially query sensitive configuration data, modify plugin parameters, or trigger state-changing actions that should be restricted to administrators.\nThe exploit does not require any specialized user interaction or social engineering; it is a direct interaction with the vulnerable plugin component via the network.\nSince this is an access control vulnerability rather than a code injection flaw, the behavior is constrained by the existing functions available within the plugin; however, if these functions contain further business logic that handles payment keys or transaction records, the impact is compounded by the exposure of financial data or site operational integrity.\nThe vulnerability is primarily exposed due to the lack of restrictive logic within the plugin's routing or request-handling functions. To exploit this, the attacker needs only to know the endpoint URI and the parameters expected by the function. Once sent, the server accepts the input as trusted, leading to full unauthorized access to the impacted feature set."
}