PayU India WordPress Plugin Authentication Bypass Vulnerability Allowing Account Takeover

Vulnerability

A vulnerability allowing authentication bypass has been identified in the PayU India WordPress plugin, affecting versions through 3.8.5. This vulnerability allows malicious actors to abuse authentication mechanisms, potentially leading to unauthorized actions that should be restricted to users with higher privileges, such as administrative access.

Impact

Exploitation of this vulnerability could allow an attacker to bypass authentication and gain administrative privileges on the affected WordPress site, leading to unauthorized access and control over the site.

Remediation

Users of the PayU India WordPress plugin are advised to update to the latest version. For those unable to update immediately, Patchstack offers a virtual patch that can be applied to mitigate this vulnerability.

Added: Jun 9, 2025, 4:58 PM
Updated: Jun 9, 2025, 4:58 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
7.4
remediation
0.0
relevance
0.2
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.