← Voltar para CVEs
CVE-2025-15400
MEDIUM6.5
Descricao
The OpenPix for WooCommerce WordPress plugin through 2.13.3 allows any authenticated user to trigger AJAX actions that reset payment gateway configuration options without capability or nonce checks. This permits any authenticated users, such as subscribers to clear API credentials and webhook status, causing persistent disruption of OpenPix payment functionality.
Detalhes CVE
Pontuacao CVSS v3.16.5
SeveridadeMEDIUM
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosLOW
Interacao do usuarioNONE
Publicado2/11/2026
Ultima modificacao4/2/2026
Fontenvd
Avistamentos honeypot0
Fraquezas (CWE)
CWE-862
Referencias
https://wpscan.com/vulnerability/54c1251f-96be-4d70-b773-3db26b599838/(contact@wpscan.com)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.