CVE-2025-15513: Float Payment Gateway <= 1.1.9 - Improper Authorization to Unauthenticated Order Status Manipulation
The Float Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to improper error handling in the verifyFloatResponse() function in all versions up to, and including, 1.1.9. This makes it possible for unauthenticated attackers to mark any WooCommerce order as failed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15513?
CVE-2025-15513 has a severity rating that indicates a critical risk due to unauthorized data manipulation.
How do I fix CVE-2025-15513?
To fix CVE-2025-15513, upgrade the Float Payment Gateway plugin to version 1.2.0 or later.
What versions are affected by CVE-2025-15513?
CVE-2025-15513 affects all versions of the Float Payment Gateway plugin for WordPress up to and including 1.1.9.
What kind of vulnerability is CVE-2025-15513?
CVE-2025-15513 is an improper authorization vulnerability that allows unauthenticated users to manipulate order statuses.
Which function in the Float Payment Gateway is associated with CVE-2025-15513?
The verifyFloatResponse() function is associated with CVE-2025-15513 and contains the improper error handling issue.