CVE-2025-12883
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-12883 is an unauthenticated payment bypass vulnerability in the Campay Woocommerce Payment Gateway plugin for WordPress. It affects all versions up to and including 1.2.2, allowing remote attackers to mark orders as successfully completed without actually completing a payment transaction. The vulnerability was published on December 12, 2025, and was assigned by Wordfence. It carries a CVSS v3.1 base score of 5.3 (Medium) (Wordfence, Red Hat CVE).

Technical details

The root cause is improper transaction validation (CWE-639: Authorization Bypass Through User-Controlled Key), where the plugin fails to verify that a legitimate payment transaction has actually been processed through the Campay payment gateway before marking an order as complete. An unauthenticated attacker can manipulate user-controlled input (such as order or transaction identifiers) to trigger the order completion logic without a corresponding valid payment. No authentication or special privileges are required, and the attack is conducted entirely over the network with low complexity (Wordfence, ENISA EUVD).

Impact

Successful exploitation allows unauthenticated attackers to fraudulently complete WooCommerce orders without making any actual payment, resulting in direct financial loss for store operators. The integrity of the order management system is compromised, as orders can be falsely marked as paid and goods or services may be dispatched without revenue. Confidentiality and availability are not directly impacted by this vulnerability (Wordfence, Red Hat CVE).

Exploitability

The vulnerability requires no authentication, no user interaction, and has low attack complexity, making it trivially exploitable by any remote attacker. The EPSS score is approximately 0.049% (0.000490), indicating a currently low probability of active exploitation in the wild. No evidence of in-the-wild exploitation, threat actor attribution, or inclusion in the CISA KEV catalog has been reported at this time (Wordfence, ENISA EUVD).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites using the Campay Woocommerce Payment Gateway plugin (versions ≤ 1.2.2) by scanning for plugin-specific files or headers (e.g., /wp-content/plugins/campay-api/).
  2. Add item to cart: Place an item in the WooCommerce store's cart and proceed to checkout, selecting Campay as the payment method to generate a valid order.
  3. Intercept or craft the callback request: Identify the payment confirmation or callback endpoint used by the plugin to mark orders as complete (typically a webhook or return URL handler).
  4. Bypass payment validation: Submit a crafted request to the callback/confirmation endpoint with a manipulated or replayed transaction identifier, exploiting the lack of server-side validation to trigger order completion without a real payment.
  5. Receive goods/services: The order is marked as paid and fulfilled by the store, resulting in financial loss to the merchant (Wordfence).

Indicators of compromise

  • Logs: WordPress/WooCommerce access logs showing POST requests to the Campay plugin's callback or return URL endpoint from unexpected or unauthenticated sources; orders transitioning to 'completed' or 'processing' status without a corresponding valid Campay transaction ID in payment gateway records.
  • Application: WooCommerce orders marked as paid with missing, duplicate, or invalid Campay transaction references; orders completed with no matching transaction in the Campay payment gateway dashboard.
  • Network: Repeated or automated requests to the plugin's payment confirmation endpoint from a single IP or range, especially without prior checkout flow activity.

Mitigation and workarounds

Store operators should update the Campay Woocommerce Payment Gateway plugin to version 1.2.3 or later, which addresses the improper transaction validation. Until patching is possible, consider temporarily disabling the Campay payment gateway option in WooCommerce settings to prevent exploitation. Regularly audit WooCommerce orders for anomalies such as completed orders lacking valid payment gateway transaction IDs (Wordfence, WordPress Plugin).

Community reactions

The vulnerability was reported and assigned by Wordfence, a leading WordPress security firm, and has been covered by security aggregators including VulDB and Patchstack. No notable public researcher commentary or significant social media discussion has been identified beyond standard vulnerability disclosure channels (Wordfence).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-15239NONEN/A
  • simple-cloudflare-turnstile
NoYesAug 07, 2026
CVE-2026-15211NONEN/A
  • subscriptions-for-woocommerce
NoYesAug 07, 2026
CVE-2026-15148NONEN/A
  • wp-events-manager
NoYesAug 07, 2026
CVE-2026-16265NONEN/A
  • wp-google-map-plugin
NoYesAug 07, 2026
CVE-2026-16263NONEN/A
  • wp-google-map-plugin
NoYesAug 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management