Executive brief
The Handily booking plugin for WordPress fails to verify user permissions when modifying critical payment settings. An attacker can change Stripe payment configuration without authentication, redirecting customer payments to attacker-controlled accounts and causing direct financial loss and customer fraud.
Technical details
Missing authorization checks on payment settings endpoints allow unauthenticated attackers to modify Stripe credentials including publishable keys, secret keys, and payment URLs via direct parameter manipulation. The vulnerability requires network access but no authentication or user interaction; successful exploitation allows complete control over payment processing configuration. A patch is referenced in the advisory.
Affected products
- Handily Handily up to and including 1.0.3
Timeline
- 2026-09-22: disclosed