Executive brief
The PayPlus Payment Gateway plugin for WordPress, which facilitates online transactions for WooCommerce stores, contains a security flaw in how it handles order updates. An unauthorized person can exploit this to view private order keys for any customer and, in certain cases, change the status of an order (e.g., from pending to processing). This could lead to the exposure of customer order details and potential disruption of the store's fulfillment process.
Technical details
The PayPlus Payment Gateway plugin fails to implement proper authorization checks and order-ownership validation within the 'complete_order' AJAX action. An unauthenticated attacker can trigger this action by providing a valid 'frontNonce' (which is publicly accessible on the checkout page) and a target 'order_id'. Because order IDs are typically sequential, an attacker can enumerate orders to disclose their secret WooCommerce order keys via the 'redirect_url' in the JSON response. Furthermore, if an order has an existing successful PayPlus response but hasn't reached the final success state, this request can force a status transition (e.g., from 'pending' to 'processing') without valid payment verification. The issue is fixed in version 8.2.2.
Affected products
- PayPlus PayPlus Payment Gateway < 8.2.2
Timeline
- 2026-06-29: disclosed: Publicly published by WPScan
- 2026-07-20: advisory: NVD publication date
- 2026-08-22: patched: Fixed in version 8.2.2