CVE-2026-12972
Received Received - Intake

Unauthenticated Order Metadata Tampering in PayPlus Payment Gateway

Vulnerability report for CVE-2026-12972, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-20

Last updated on: 2026-07-20

Assigner: WPScan

Description

The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to tamper with the payment-related metadata of arbitrary WooCommerce orders.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-20
Last Modified
2026-07-20
Generated
2026-07-21
AI Q&A
2026-07-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
payplus payment_gateway to 8.2.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the PayPlus Payment Gateway WordPress plugin before version 8.2.2. It allows unauthenticated users to modify payment-related metadata of any WooCommerce order by exploiting an AJAX action in the plugin. Attackers can overwrite the payplus_page_request_uid meta field of arbitrary orders through crafted POST requests to admin-ajax.php.

Detection Guidance

Check if your PayPlus Payment Gateway plugin version is below 8.2.2. Inspect network traffic for POST requests to admin-ajax.php with parameters modifying payplus_page_request_uid. Look for unauthorized changes to WooCommerce order metadata.

Impact Analysis

This flaw could allow attackers to tamper with order payment details, potentially leading to unauthorized changes in transaction metadata. If combined with a payment bypass, attackers with a valid merchant account might manipulate order statuses or payment processing, affecting financial transactions and order integrity.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by allowing unauthorized modifications to payment metadata in WooCommerce orders. Unauthenticated attackers could alter payment-related details, potentially leading to improper financial processing or data integrity issues. This may violate principles of data protection and secure transaction handling required by these regulations.

Mitigation Strategies

Update the PayPlus Payment Gateway plugin to version 8.2.2 or later immediately. Review all WooCommerce orders for suspicious metadata changes. Implement additional access controls to restrict admin-ajax.php requests.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12972. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart