PT-2026-39949 · Ipospays · Ipospays Gateways Wc

Alexis Lafontaine

·

Published

2026-05-12

·

Updated

2026-05-12

·

CVE-2026-4663

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The iPOSpays Gateways WC plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.3.7. This is due to the plugin exposing a REST API endpoint /wp-json/ipospays/v1/save settings with 'permission callback' set to ' return true', which allows unauthenticated access without any capability checks or nonce verification. This makes it possible for unauthenticated attackers to update plugin settings, specifically allowing them to overwrite critical payment gateway settings including live API keys, secret keys, and payment tokens stored in the 'woocommerce ipospays settings' option.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-4663

Affected Products

Ipospays Gateways Wc