PT-2026-7486 · WordPress · Pix Para Woocommerce

Published

2026-02-11

·

Updated

2026-02-11

·

CVE-2025-15400

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Pix para Woocommerce WordPress plugin versions through 2.13.3
Description The plugin allows any authenticated user to trigger AJAX actions that reset payment gateway configuration options without proper capability or nonce checks. This allows authenticated users, including those with subscriber privileges, to clear API credentials and webhook status, leading to persistent disruption of OpenPix payment functionality.
Recommendations Update Pix para Woocommerce to a version later than 2.13.3.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-15400

Affected Products

Pix Para Woocommerce