PT-2026-7486 · WordPress · Pix Para Woocommerce

CVE-2025-15400

·

Publicado

2026-02-11

·

Atualizado

2026-02-11

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Pix para Woocommerce WordPress plugin versions through 2.13.3
Description The plugin allows any authenticated user to trigger AJAX actions that reset payment gateway configuration options without proper capability or nonce checks. This allows authenticated users, including those with subscriber privileges, to clear API credentials and webhook status, leading to persistent disruption of OpenPix payment functionality.
Recommendations Update Pix para Woocommerce to a version later than 2.13.3.

Exploit

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-15400

Produtos afetados

Pix Para Woocommerce