Splitit WordPress Plugin Missing Authorization Vulnerability in Payment Gateway File

Vulnerability

A vulnerability exists in the Splitit plugin for WordPress, all versions through 4.2.8, due to inadequate capability checks in the 'splitIt-flexfields-payment-gateway.php' file. This flaw allows authenticated attackers with Subscriber-level access or higher to unauthorizedly modify plugin settings, such as switching the environment between sandbox and production.

Impact

Exploitation of this vulnerability could lead to unauthorized changes in plugin settings, potentially disrupting payment processing or causing other operational issues.

Remediation

Users are advised to update the Splitit WordPress plugin to version 4.2.9 or a newer patched version.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.2
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.