Executive brief
iPOSpays Gateways WC is a WordPress plugin used to integrate payment processing into e-commerce websites. A security flaw in the plugin allows unauthorized individuals to bypass access controls, potentially leading to unauthorized changes to site settings or payment configurations. This could impact the integrity of the checkout process or business operations.
Technical details
The iPOSpays Gateways WC plugin for WordPress (versions up to and including 1.3.7) is vulnerable to broken access control due to missing authorization checks (CWE-862). This vulnerability allows a remote, unauthenticated attacker to execute functions or access security levels that should be restricted to higher-privileged users. The root cause is a failure to validate user permissions or implement proper nonce tokens before performing sensitive actions. An attacker can exploit this over the network without user interaction to modify plugin configurations. The issue is resolved in version 1.3.8.
Affected products
- iPOSPays iPOSpays Gateways WC <= 1.3.7
Timeline
- 2026-01-08: other: Vulnerability reported by researcher
- 2026-02-07: advisory: Patchstack published advisory
- 2026-02-07: patched: Version 1.3.8 released to address the issue
- 2026-04-08: disclosed: CVE published to NVD