What the vulnerability does
01Description
Missing Authorization vulnerability in BitPay BitPay Checkout for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BitPay Checkout for WooCommerce: from n/a through 4.1.0.
Explanation of Vulnerability in Simple Terms
02Summary
BitPay Checkout for WooCommerce versions up to 4.1.0 lack proper authorization checks on certain operations. An attacker on the network can modify data without authentication or user interaction. The vulnerability affects the integrity of transactions or settings processed through the plugin.
What an attacker can do
03Attacker Capabilities
Modify payment or checkout data without logging in.
Potential impact on your site
04Site Impact
Attackers can alter payment information, order details, or plugin settings without authorization.
Conditions required to exploit
05Prerequisites
Network access to the WooCommerce site; no authentication required.
Key dates
06Disclosure timeline
December 13, 2024
CVE published
April 28, 2026
Record updated