Executive brief
Autopay dla WooCommerce is a WordPress plugin used by online stores to process payments. A security flaw in versions 2.2.27 and earlier allows unauthorized individuals to bypass access controls, potentially interfering with payment processing or administrative functions. This could lead to unauthorized changes to order statuses or disruption of the checkout process, impacting business operations and customer trust.
Technical details
The Autopay dla WooCommerce plugin for WordPress (versions <= 2.2.27) is vulnerable to broken access control due to missing authorization checks (CWE-862). An unauthenticated remote attacker can exploit this vulnerability to execute functions that should be restricted to higher-privileged users. The vulnerability stems from a lack of proper validation of user permissions or nonce tokens in specific plugin components. Successful exploitation could allow an attacker to modify data or disrupt service availability. The issue is addressed in version 2.2.28.
Affected products
- WP Desk Autopay dla WooCommerce <= 2.2.27
Timeline
- 2026-06-08: other: Reported by researcher Averon Averenkov
- 2026-07-16: advisory: Patchstack advisory published
- 2026-07-23: disclosed: CVE published to NVD
- 2026-07-23: patched: Patch available in version 2.2.28