Executive brief
Wava Payment is a WordPress plugin used to process payments on websites. A security flaw in the plugin allows unauthorized individuals to bypass access controls, potentially allowing them to perform actions or modify settings that should be restricted to administrators. This could lead to unauthorized changes to payment configurations or other site settings.
Technical details
A missing authorization vulnerability (CWE-862) exists in the Wava.co Wava Payment plugin for WordPress through version 0.3.9. The flaw stems from incorrectly configured access control security levels, which fail to properly validate user permissions before executing certain functions. An unauthenticated remote attacker can exploit this by sending crafted requests to the affected site, potentially allowing them to perform actions that should require higher privileges. As of the latest advisory, no official patch has been released by the vendor.
Affected products
- Wava.co Wava Payment <= 0.3.9
Timeline
- 2026-01-08: other: Vulnerability reported by researcher
- 2026-02-07: advisory: Patchstack published initial advisory
- 2026-04-08: disclosed: CVE published to NVD