Executive brief
The Peach Payments Gateway plugin for WordPress, which allows online stores to process customer payments, contains a security flaw in its access control settings. An unauthorized individual could exploit this to perform actions they should not be allowed to, potentially interfering with order processing or site integrity. While the impact is considered moderate, it could affect the reliability of payment operations for businesses using this plugin.
Technical details
A Broken Access Control vulnerability (CWE-862: Missing Authorization) exists in the Peach Payments Gateway plugin (wc-peach-payments-gateway) for WordPress through version 4.0.2. The flaw stems from a failure to properly validate user permissions or authentication tokens before executing specific functions. An unauthenticated remote attacker can exploit this to perform unauthorized actions, potentially impacting the integrity and availability of the payment gateway's operations. The issue is resolved in version 4.0.3.
Affected products
- Peach Payments Peach Payments Gateway (wc-peach-payments-gateway) <= 4.0.2
Timeline
- 2026-04-30: disclosed: Reported by HieuPenguinnn to Patchstack
- 2026-07-08: advisory: Initial advisory published by Patchstack
- 2026-07-13: advisory: CVE published in NVD dataset
- 2026-07-08: patched: Version 4.0.3 released to address the vulnerability