Oceanpayment CreditCard Gateway <= 6.0 - Missing Authentication to Unauthenticated Order Status Update

2025-10-14 19:36
Jonas Benjamin Friedli

Strategic Overview

Status
Unpatched
Affected Version<= 6.0
CVSS5.3Medium
CVECVE-2025-11728
View all Oceanpayment CreditCard Gateway vulnerabilities

Vulnerability Overview

The Oceanpayment CreditCard Gateway plugin for WordPress is vulnerable to unauthenticated and unauthorized modification of data due to missing authentication and capability checks on the 'return_payment' and 'notice_payment' functions in all versions up to, and including, 6.0. This makes it possible for unauthenticated attackers to update WooCommerce orders to 'failed' status, and update transaction IDs.

Technical Analysis

REMEDIATION: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement. --- IDENTIFIER: CWE-306 (Missing Authentication for Critical Function) The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C