Executive brief
The zipMoney Payments Plugin for WooCommerce is a payment gateway extension used in WordPress e-commerce sites. The plugin fails to validate user permissions on a frontend function, allowing attackers to delete critical site configuration without authentication. This can disable security settings, deactivate plugins, and take the website offline, disrupting business operations and customer access.
Technical details
The vulnerability is a missing authorization check (CWE-862) in a frontend request handler. The plugin processes unauthenticated requests and permits deletion of arbitrary WordPress options without validating the caller's identity or permissions. An attacker can craft requests to delete essential options such as access control settings, plugin configuration, and core site configuration, resulting in complete site compromise and availability loss. No authentication or user interaction is required; the attack is fully remote. The vulnerability affects versions before 2.4.0, which contains the fix.
Affected products
- Zip Co Payments Plugin for WooCommerce before 2.4.0
Timeline
- 2026-09-08: disclosed
- 2026-09-10: patched: Fixed in version 2.4.0