PayPlus Payment Gateway
cpe:2.3:a:payplus:payplus_payment_gateway:*:*:*:*:wordpress:*:*
- < 8.2.2
A vulnerability exists in the PayPlus Payment Gateway WordPress plugin in versions prior to 8.2.2. The issue arises because the plugin's AJAX actions, accessible to unauthenticated users, lack proper authorization and order-ownership validation. This flaw enables the disclosure of secret order keys for arbitrary WooCommerce orders and, in some cases, allows modification of order statuses.
Exploitation of this vulnerability could lead to unauthorized disclosure of WooCommerce order secret keys and unauthorized modification of order statuses, such as changing an order from 'pending' to 'processing'.
To reproduce this vulnerability, first ensure that the PayPlus Payment Gateway plugin version 8.2.1 or earlier is installed and activated on a WordPress site with WooCommerce. As an unauthenticated user, add a product to the cart and navigate to the checkout page. Scrape the localized frontNonce from the HTML. Then, send a POST request to 'wp-admin/admin-ajax.php' with the action 'complete_order', including the scraped nonce and the ID of an arbitrary order. The response will reveal the secret order key for the specified order. If the order has a stored successful PayPlus response but is not yet in the success status, the same AJAX call can be used to change the order status without authorization.
Users are advised to update the PayPlus Payment Gateway WordPress plugin to version 8.2.2 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.