Sceawere

Vulnerability Detail

CVE-2026-95597UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Missing Authorization in SimplePay PG

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
3h ago
Vendor
codemstory
Product
워드프레스 결제 심플페이
Attack Type
Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Missing Authorization vulnerability in codemstory 워드프레스 결제 심플페이 pgall-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 워드프레스 결제 심플페이: from n/a through 5.5.17.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-09T10:16:42.510Z",
  "pubdate": "2026-10-09T10:16:42.510Z",
  "executiveSummary": "The WordPress plugin '워드프레스 결제 심플페이 pgall-for-woocommerce' is susceptible to a Missing Authorization vulnerability.\nThe vulnerability originates from improperly configured access control security levels within the plugin's architectural framework.\nThis flaw allows unauthorized actors to invoke restricted functionalities or access sensitive transaction data without undergoing requisite authentication or authorization protocols.\nThe issue affects versions ranging from n/a through 5.5.17.\nThe risk implication is significant, as it permits attackers to manipulate payment processing or retrieve internal transaction configurations, potentially leading to financial fraud, unauthorized data disclosure, or disruption of payment services.\nExploitation does not require elevated privileges, enabling remote unauthenticated or low-privileged attackers to interact with internal API endpoints or administrative functions that were intended to be restricted.\nSuccessful exploitation compromises the integrity and confidentiality of the payment gateway integration, necessitating immediate security review and potential restriction of access to the affected endpoints.",
  "technicalDetails": "The vulnerability is classified as a Missing Authorization flaw, specifically stemming from the failure of the plugin to implement robust access control checks on its exposed administrative or transaction-related endpoints.\nIn the context of '워드프레스 결제 심플페이 pgall-for-woocommerce', the software fails to verify the authorization level of the requesting user when performing operations that modify payment settings or retrieve sensitive transaction metadata.\nThe root cause lies in the oversight of implementing security hooks or standard WordPress capability checks (such as 'current_user_can') within the controller functions responsible for processing payment gateway configurations and backend administrative requests.\nThe exploitation flow begins with an attacker identifying the specific vulnerable endpoint or AJAX action registered by the plugin. By crafting a malformed request—typically an HTTP GET or POST request targeting these unprotected hooks—the attacker bypasses the authentication layer completely.\nSince the backend fails to validate the requester's identity or administrative rights, the server processes the request as if it originated from an authorized administrator. This allows the attacker to execute backend logic, such as modifying PG keys, changing account credentials, or exposing customer transaction logs.\nThe impact is heightened because the vulnerable component is directly integrated into the payment flow, meaning any configuration tampering could redirect legitimate customer payments to attacker-controlled accounts or cause a complete breakdown of the merchant's ability to process transactions.\nThis vulnerability is reachable over the network and does not require specific user interaction, provided the attacker knows or can guess the relevant endpoint URLs. Post-exploitation, an attacker can maintain persistence by altering administrative settings or exfiltrating sensitive PII (Personally Identifiable Information) regarding previous payment transactions stored within the WordPress database.\nBecause the plugin lacks granular authorization, it provides a broad attack surface for any unauthenticated actor to perform privileged operations, effectively granting them control over the payment gateway integration component within the WordPress environment."
}
CVE-2026-95597: Missing Authorization in SimplePay PG (MEDIUM Severity, CVSS: 6.5) | Sceawere