CVE-2025-14487
Received Received - Intake

Unauthenticated Payment Settings Modification in Handily WordPress Plugin

Vulnerability report for CVE-2025-14487, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-22

Last updated on: 2026-09-22

Assigner: Wordfence

Description

The Handily plugin for WordPress is vulnerable to unauthorized payment settings modification due to missing authorization checks in all versions up to, and including, 1.0.3. This makes it possible for unauthenticated attackers to modify Stripe payment configuration settings, including publishable keys, secret keys, email addresses, success URLs, and cancel URLs via the payment settings parameters. This could allow attackers to redirect payments to their own Stripe accounts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-22
Last Modified
2026-09-22
Generated
2026-09-22
AI Q&A
2026-09-22
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
handily plugin to 1.0.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Handily plugin for WordPress allows unauthenticated attackers to modify Stripe payment settings due to missing authorization checks. This includes changing publishable keys, secret keys, email addresses, success URLs, and cancel URLs via payment settings parameters.

Detection Guidance

Check for unauthorized modifications to Stripe payment settings in the Handily plugin. Review plugin files for changes to publishable keys, secret keys, email addresses, success URLs, or cancel URLs. Look for suspicious network requests to Stripe API endpoints from unauthenticated sources.

Impact Analysis

Attackers could redirect payments to their own Stripe accounts, potentially stealing money from transactions. This could lead to financial loss for users or customers making payments through the affected WordPress site.

Compliance Impact

This vulnerability could violate compliance with GDPR by exposing payment data to unauthorized parties. For HIPAA, if payment data includes protected health information, unauthorized access could lead to breaches of patient confidentiality.

Mitigation Strategies

Update the Handily plugin to the latest version if available. Disable the plugin if no update is available. Review and reset all Stripe payment settings. Monitor for unauthorized transactions and revoke any suspicious API keys.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-14487. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart