CVE-2025-15400: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-15400 is a Missing Authorization vulnerability in the OpenPix for WooCommerce WordPress plugin (versions through 2.13.3) that allows any authenticated user — including low-privilege subscribers — to reset payment gateway configuration options via unprotected AJAX actions. The vulnerability was added to WPScan on 2026-01-13 and publicly disclosed on 2026-01-20. It carries a CVSS v3.1 base score of 6.5 (Medium) (WPScan, Red Hat CVE).

Technical details

The root cause is CWE-862 (Missing Authorization): the plugin registers AJAX action handlers (e.g., openpix_prepare_oneclick) accessible via wp-admin/admin-ajax.php without performing any capability checks or nonce validation. Because WordPress's admin-ajax.php endpoint is accessible to any logged-in user, a subscriber-level account can POST to this endpoint with the appropriate action parameter and trigger a full reset of the OpenPix payment gateway settings, including clearing the AppID and webhook status. No special privileges, social engineering, or complex preconditions are required beyond holding a valid authenticated session (WPScan, Red Hat CVE).

Impact

Successful exploitation results in persistent disruption of the OpenPix Pix payment gateway on affected WooCommerce stores: API credentials (AppID) and webhook configuration are cleared, rendering the payment method non-functional until manually reconfigured by an administrator. While there is no direct confidentiality impact (credentials are not exposed to the attacker), the integrity of the payment gateway configuration is fully compromised, and the availability of the payment processing service is effectively denied to customers. Repeated exploitation by a malicious subscriber could cause sustained business disruption and revenue loss for the affected merchant (WPScan).

Exploitability

A public proof-of-concept (PoC) cURL command is included in the WPScan advisory, making exploitation trivial for any authenticated user. The EPSS score is 0.005% (very low), and there is no evidence of active in-the-wild exploitation or inclusion in CISA's Known Exploited Vulnerabilities (KEV) catalog as of the time of reporting. No threat actor attribution has been identified (WPScan, Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify a WordPress/WooCommerce site using the OpenPix for WooCommerce plugin (version ≤ 2.13.3) by inspecting page source, plugin enumeration tools, or WooCommerce payment method indicators.
  2. Obtain authenticated session: Register or log in as any low-privilege user (e.g., a customer/subscriber account) on the target WordPress site.
  3. Retrieve session cookies: Use browser developer tools to capture the wordpress_logged_in_* authentication cookie from the authenticated session.
  4. Send malicious AJAX request: Execute the following cURL command targeting the unprotected AJAX endpoint:
curl -i -X POST "http://example.com/wp-admin/admin-ajax.php" \
  -H "Content-Type: application/x-www-form-urlencoded" \
  -H "Cookie: wordpress_logged_in_xxxx=xxxx" \
  --data "action=openpix_prepare_oneclick"
  1. Confirm impact: Navigate to WooCommerce >> Settings >> Payments >> OpenPix Pix on the admin panel to verify that the AppID and other configuration details have been reset, confirming successful exploitation (WPScan).

Indicators of compromise

  • Network: Unexpected HTTP POST requests to /wp-admin/admin-ajax.php with the body parameter action=openpix_prepare_oneclick originating from non-administrative user sessions or unusual IP addresses.
  • Logs: WordPress/web server access logs showing repeated POST requests to admin-ajax.php with openpix_prepare_oneclick action from subscriber-level accounts; sudden loss of OpenPix payment gateway configuration logged in WooCommerce event logs.
  • Application: OpenPix payment gateway settings (AppID, webhook status) found cleared or reset without corresponding administrator activity in the WordPress audit log.

Mitigation and workarounds

As of the time of disclosure, there is no known fixed version of the OpenPix for WooCommerce plugin (the WPScan advisory lists "No known fix"). Site administrators should consider deactivating or removing the plugin until a patched version is released. As a compensating control, restrict user registration on the WordPress site to prevent untrusted users from obtaining authenticated sessions, and monitor WooCommerce payment gateway settings for unauthorized changes (WPScan).

Community reactions

The vulnerability was discovered and reported by security researcher Md. Moniruzzaman Prodhan (NomanProdhan), who submitted it to WPScan. A brief technical write-up was published by Infinit Security at infinitsec.net. No significant vendor statements, broader media coverage, or notable community discussion have been identified beyond standard vulnerability database entries (WPScan).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management