Executive brief
The PayPlus Payment Gateway plugin for WordPress, which allows online stores to process credit card payments, contains a security flaw in how it handles order updates. An unauthorized person can remotely modify internal payment data associated with customer orders without needing to log in. This could potentially allow an attacker to manipulate the payment status of an order, leading to financial loss or fraudulent order fulfillment.
Technical details
The vulnerability is an Improper Access Control (CWE-284) within the 'make-hosted-payment' AJAX action. The plugin fails to verify if the user requesting the action has the appropriate permissions or ownership of the specified 'order_id'. An unauthenticated attacker can exploit this by sending a crafted POST request to 'admin-ajax.php' with a valid 'frontNonce' to overwrite the 'payplus_page_request_uid' metadata of any WooCommerce order. This metadata tampering can potentially be chained to bypass payment verification if the attacker provides a transaction ID from a legitimate payment they made, as the internal IPN routine does not sufficiently validate the transaction amount or ID against the specific order. The issue is resolved in version 8.2.2.
Affected products
- PayPlus PayPlus Payment Gateway < 8.2.2
Timeline
- 2026-06-29: disclosed: Publicly published by WPScan
- 2026-07-20: advisory: NVD publication date