CyberRota Analysis
AI-GeneratedThe PayPlus Payment Gateway plugin for WordPress versions prior to 8.2.2 is vulnerable due to inadequate authorization and order-ownership validation in an AJAX action accessible to unauthenticated users. This flaw allows attackers to manipulate payment-related metadata for any WooCommerce order, potentially leading to unauthorized transactions or data breaches. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of exploitation.
Original NVD Description
The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to tamper with the payment-related metadata of arbitrary WooCommerce orders.