CVE-2025-11728

⚪ Do wiadomości

Brak uwierzytelnienia w wtyczce Oceanpayment dla WordPressa pozwala na nieautoryzowaną modyfikację zamówień.

CVSS
5.3
EPSS
0.3%
Exploit
none
Vendor
Opis źródłowy (NVD)

The Oceanpayment CreditCard Gateway plugin for WordPress is vulnerable to unauthenticated and unauthorized modification of data due to missing authentication and capability checks on the 'return_payment' and 'notice_payment' functions in all versions up to, and including, 6.0. This makes it possible for unauthenticated attackers to update WooCommerce orders to 'failed' status, and update transaction IDs.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS5.3
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.3%
Opublikowano (NVD)2025-10-15 09:15:43 UTC
Ostatnia modyfikacja (NVD)2026-10-08 12:10:00 UTC
Referencje