Sceawere

Vulnerability Detail

CVE-2026-66431UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated Broken Access Control in WooCommerce Bitcoin Lightning Payment Gateway

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
7h ago
Vendor
WoompaLoompa
Product
Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK)
Attack Type
CWE-862 Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) <= 1.0.7 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-08-13T14:17:05.120Z",
  "pubdate": "2026-08-13T14:17:05.120Z",
  "executiveSummary": "An unauthenticated broken access control vulnerability has been identified in the Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) plugin affecting versions 1.0.7 and prior.\nThis security flaw allows unauthenticated remote attackers to bypass authorization controls and interact with sensitive plugin endpoints without requiring valid user sessions or administrative privileges.\nThe vulnerability directly impacts e-commerce platforms running the affected WordPress plugin, potentially leading to unauthorized manipulation of payment processing routines, transaction state bypasses, or exposure of internal gateway functionalities.\nThe risk implication is critical as payment gateways handle financial transactions and sensitive state logic; successful exploitation compromises the integrity and confidentiality of the payment infrastructure.\nAttackers require network connectivity to the target WordPress instance hosting the vulnerable WooCommerce plugin and do not need any pre-existing authentication or specific role privileges to execute the attack.\nExploitation requirements are minimal, relying solely on the ability to craft HTTP requests targeting the improperly secured access points exposed by the CLINK payment gateway integration.",
  "technicalDetails": "The root cause of the vulnerability stems from inadequate access control checks and improper authorization enforcement within the request handling mechanisms of the Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) plugin.\nThe affected component involves the routing and endpoint handling logic utilized by the CLINK integration to process payment callbacks, status checks, or administrative actions.\nThe affected versions include Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) <= 1.0.7.\nAuthentication and privilege requirements are entirely absent; the vulnerability manifests as an unauthenticated vector where access controls are either omitted or fail to validate the caller's identity and permissions before executing sensitive operations.\nThe network exposure is public-facing, as the vulnerable endpoints are accessible via standard HTTP/HTTPS requests over the internet on any WordPress installation utilizing the affected plugin.\nThe attack flow proceeds as follows: First, an unauthenticated attacker identifies the exposed HTTP endpoints associated with the CLINK payment gateway plugin. Second, the attacker crafts a malicious HTTP request directed at these unprotected endpoints, bypassing the intended authorization layer. Third, the plugin processes the incoming request without validating authentication tokens, session identifiers, or user capabilities. Finally, the attacker achieves unauthorized execution of the underlying gateway functionality, potentially altering transaction states or interacting with sensitive backend routines.\nPost-exploitation impact includes the potential unauthorized processing or validation of fraudulent payments, interference with merchant revenue collection, and unauthorized access to internal payment gateway operations, thereby undermining the transactional integrity of the WooCommerce store."
}
CVE-2026-66431: Unauthenticated Broken Access Control in WooCommerce Bitcoin Lightning Payment Gateway (HIGH Severity, CVSS: 7.5) - Sceawere