PayMaster for WooCommerce Server-Side Request Forgery Vulnerability

Vulnerability

A Server-Side Request Forgery (SSRF) vulnerability exists in the PayMaster for WooCommerce WordPress plugin, affecting all versions through 0.4.31. The vulnerability arises in the 'wp_ajax_paym_status' AJAX action, allowing authenticated attackers with Subscriber-level access and above to send web requests to arbitrary locations. This could be exploited to query and modify information from internal services.

Impact

Exploitation of this vulnerability allows for Server-Side Request Forgery, enabling attackers to make requests from the vulnerable server to internal services or external systems, potentially leading to unauthorized information access or modification.

Remediation

No known patch is available. It is recommended to uninstall the affected plugin and find a replacement.

Added: Jul 4, 2025, 3:28 AM
Updated: Jul 4, 2025, 3:28 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.9
exploitability
5.2
remediation
0.0
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.