PT-2026-2839 · Aplazopayment · Aplazo Payment Gateway

Published

2026-01-14

·

Updated

2026-01-14

·

CVE-2025-15512

CVSS v3.1
5.3
VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The Aplazo Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the check success response() function in all versions up to, and including, 1.4.2. This makes it possible for unauthenticated attackers to set any WooCommerce order to
pending payment
status.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-15512

Affected Products

Aplazo Payment Gateway