Campay Woocommerce Payment Gateway <= 1.2.2 - Unauthenticated Payment Bypass

Strategic Overview

Status
Patched in 1.2.3
Affected Version<= 1.2.2
CVSS5.3Medium
CVECVE-2025-12883
View all Campay Woocommerce Payment Gateway vulnerabilities

Vulnerability Overview

The Campay Woocommerce Payment Gateway plugin for WordPress is vulnerable to Unauthenticated Payment Bypass in all versions up to, and including, 1.2.2. This is due to the plugin not properly validating that a transaction has occurred through the payment gateway. This makes it possible for unauthenticated attackers to bypass payments and mark orders as successfully completed resulting in a loss of income.

Technical Analysis

REMEDIATION: Update to version 1.2.3, or a newer patched version --- IDENTIFIER: CWE-639 (Authorization Bypass Through User-Controlled Key) The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C