PT-2025-50811 · WordPress · Pays – Woocommerce Payment Gateway

Published

2025-12-12

·

Updated

2025-12-12

·

CVE-2025-12883

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Campay Woocommerce Payment Gateway versions up to and including 1.2.2
Description The Campay Woocommerce Payment Gateway plugin for WordPress is susceptible to an unauthenticated payment bypass. The plugin does not adequately verify that a transaction has been completed through the payment gateway. This allows unauthenticated attackers to circumvent payment processes and falsely mark orders as successful, potentially leading to financial loss.
Recommendations Update the Campay Woocommerce Payment Gateway plugin to a version later than 1.2.2.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2025-12883

Affected Products

Pays – Woocommerce Payment Gateway