
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-12883 is an unauthenticated payment bypass vulnerability in the Campay Woocommerce Payment Gateway plugin for WordPress. It affects all versions up to and including 1.2.2, allowing remote attackers to mark orders as successfully completed without actually completing a payment transaction. The vulnerability was published on December 12, 2025, and was assigned by Wordfence. It carries a CVSS v3.1 base score of 5.3 (Medium) (Wordfence, Red Hat CVE).
The root cause is improper transaction validation (CWE-639: Authorization Bypass Through User-Controlled Key), where the plugin fails to verify that a legitimate payment transaction has actually been processed through the Campay payment gateway before marking an order as complete. An unauthenticated attacker can manipulate user-controlled input (such as order or transaction identifiers) to trigger the order completion logic without a corresponding valid payment. No authentication or special privileges are required, and the attack is conducted entirely over the network with low complexity (Wordfence, ENISA EUVD).
Successful exploitation allows unauthenticated attackers to fraudulently complete WooCommerce orders without making any actual payment, resulting in direct financial loss for store operators. The integrity of the order management system is compromised, as orders can be falsely marked as paid and goods or services may be dispatched without revenue. Confidentiality and availability are not directly impacted by this vulnerability (Wordfence, Red Hat CVE).
The vulnerability requires no authentication, no user interaction, and has low attack complexity, making it trivially exploitable by any remote attacker. The EPSS score is approximately 0.049% (0.000490), indicating a currently low probability of active exploitation in the wild. No evidence of in-the-wild exploitation, threat actor attribution, or inclusion in the CISA KEV catalog has been reported at this time (Wordfence, ENISA EUVD).
/wp-content/plugins/campay-api/).Store operators should update the Campay Woocommerce Payment Gateway plugin to version 1.2.3 or later, which addresses the improper transaction validation. Until patching is possible, consider temporarily disabling the Campay payment gateway option in WooCommerce settings to prevent exploitation. Regularly audit WooCommerce orders for anomalies such as completed orders lacking valid payment gateway transaction IDs (Wordfence, WordPress Plugin).
The vulnerability was reported and assigned by Wordfence, a leading WordPress security firm, and has been covered by security aggregators including VulDB and Patchstack. No notable public researcher commentary or significant social media discussion has been identified beyond standard vulnerability disclosure channels (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."