CyberRota Analysis
AI-GeneratedThe TabaPay Gateway plugin for WordPress versions up to 1.4.0 is vulnerable due to inadequate validation of payment callbacks, enabling unauthenticated attackers to gain access to any registered user account, including those with administrative privileges. This flaw poses a significant security risk as it could lead to unauthorized access and potential manipulation of user data. WordPress site administrators using this plugin should prioritize immediate updates to mitigate the risk of exploitation.
Original NVD Description
The TabaPay Gateway WordPress plugin through 1.4.0 does not validate the payment callback before establishing a session for the account associated with the referenced order, allowing unauthenticated attackers to log in as any registered user, including an administrator.