PayPlus Payment Gateway WordPress Plugin Unauthenticated Order Metadata Tampering Vulnerability

Vulnerability

A vulnerability exists in the PayPlus Payment Gateway WordPress plugin in versions prior to 8.2.2. The issue arises because the plugin's AJAX action, available to unauthenticated users, lacks proper authorization and order-ownership validation. This oversight allows users to manipulate payment-related metadata for any WooCommerce order.

Impact

Exploitation of this vulnerability allows for unauthorized modification of payment metadata on WooCommerce orders. In stores with valid PayPlus credentials, this could be chained to bypass payment processes by falsely marking orders as paid.

Reproduction

To reproduce this vulnerability, add a product to the cart as an anonymous user and navigate to the checkout page. Scrape the localized frontNonce from the HTML. Then, send a POST request to 'wp-admin/admin-ajax.php' with the action 'make-hosted-payment', including the scraped nonce, the target order ID, a value to overwrite the payment request metadata, and a flag to save the token. The response will indicate success, and the target order's metadata will reflect the tampered value.

Remediation

Users are advised to update the PayPlus Payment Gateway WordPress plugin to version 8.2.2 or later.

Added: Jul 20, 2026, 7:27 AM
Updated: Jul 20, 2026, 7:27 AM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
0.6
exploitability
9.7
remediation
7.7
relevance
10.0
threat
6.4
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.