CVE-2026-39751: WordPress PayPlug for WooCommerce (Official) plugin <= 3.1.0 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in PayPlug for WooCommerce (Official) <= 3.1.0 versions.
Unauthenticated Broken Access Control in PayPlug for WooCommerce (Official) <= 3.1.0 versions.
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or prior privileges. The network attack vector and low attack complexity indicate it can be attempted remotely without special conditions stated in the available data.
The supplied severity vector indicates high integrity impact, with no stated confidentiality or availability impact. Successful exploitation could allow unauthorized modification, although the specific affected functionality is not provided.
PayPlug for WooCommerce (Official) versions through 3.1.0 are identified as affected. The available data does not state whether any particular configuration or feature must be enabled.