Sceawere
Vulnerability Detail
CVE-2026-95589UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Missing Authorization in Deposits for WooCommerce
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 3h ago
- Vendor
- Magepeople inc.
- Product
- Deposits and Partial Payments for WooCommerce
- Attack Type
- Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Missing Authorization vulnerability in Magepeople inc. Deposits and Partial Payments for WooCommerce advanced-partial-payment-or-deposit-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Deposits and Partial Payments for WooCommerce: from n/a through 4.0.1.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-10-09T10:16:42.097Z",
"pubdate": "2026-10-09T10:16:42.097Z",
"executiveSummary": "A missing authorization vulnerability has been identified in the Deposits and Partial Payments for WooCommerce plugin, specifically within the advanced-partial-payment-or-deposit-for-woocommerce component.\nThis security flaw, classified as a broken access control vulnerability, allows unauthorized users to manipulate settings or perform actions that should be restricted to authenticated administrative users.\nThe vulnerability affects all versions from n/a through 4.0.1.\nThe risk implication is significant, as successful exploitation may allow an unauthenticated or low-privileged attacker to bypass intended access control security levels.\nThis could lead to unauthorized modification of plugin configurations, potentially enabling fraudulent payment behaviors, altering deposit terms, or performing other unauthorized administrative actions depending on the specific functions exposed without adequate authorization checks.\nThe vulnerability does not require complex exploitation techniques, as it stems from a failure to validate the caller's privileges before executing sensitive server-side operations.",
"technicalDetails": "The vulnerability resides in the core access control logic of the Deposits and Partial Payments for WooCommerce plugin. The root cause is a deficiency in the authorization middleware or explicit permission check routines that should govern access to sensitive plugin-specific functionality.\nIn a secure implementation, every REST API endpoint, AJAX handler, or controller method that triggers a state-changing operation must perform a strict capability check, typically utilizing WordPress functions such as current_user_can() or is_admin(). In this vulnerable version range, these checks are either entirely absent or incorrectly implemented, failing to verify the session's authorization context before processing the request.\nThe exploitation flow involves an attacker sending crafted HTTP requests (typically POST or GET) directly to the vulnerable endpoints associated with the plugin. Because the backend fails to validate the user's role or capabilities, the server processes the request as if it were coming from an authorized administrator.\nSpecifically, when an attacker triggers a vulnerable function, the application fails to verify if the requesting user possesses the required administrative privileges to interact with the underlying data structures. This allows an attacker to manipulate partial payment settings or deposit configurations remotely.\nThe exposure is network-based, meaning as long as the plugin is active and the endpoint is reachable, an attacker can attempt to interact with these functions without needing a valid administrative session.\nThe technical impact is characterized as an escalation of privileges, whereby an unprivileged user gains the ability to modify plugin-level settings. Post-exploitation impact could include, but is not limited to, the alteration of financial transaction parameters, the injection of malicious settings, or the bypass of transaction validation rules, thereby compromising the integrity of the WooCommerce store's deposit and payment processing lifecycle."
}