CVE-2025-15512: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-15512 is a Missing Authorization vulnerability in the Aplazo Payment Gateway plugin for WordPress, allowing unauthenticated attackers to modify WooCommerce order statuses. The flaw exists in all versions up to and including 1.4.3 of the plugin, due to a missing capability check on the check_success_response() function. It was initially disclosed on January 14, 2026, with the affected version range later updated to include 1.4.3 on April 8, 2026. It carries a CVSS v3.1 base score of 5.3 (Medium), assigned by Wordfence (Wordfence, Red Hat CVE).

Technical details

The root cause is CWE-862 (Missing Authorization): the check_success_response() function in class-aplazo-module.php (line 206) does not perform any capability or authentication check before processing requests (WordPress Trac). Because this function is accessible over the network without any privilege requirements, an unauthenticated remote attacker can invoke it directly via an HTTP request. The attack vector is network-based, requires no user interaction, and has low attack complexity, making it trivially exploitable against any site running the vulnerable plugin versions (Wordfence).

Impact

Successful exploitation allows any unauthenticated attacker to set any WooCommerce order to pending payment status, regardless of its actual payment state. This integrity impact could be abused to disrupt order fulfillment workflows, cause financial discrepancies, or potentially manipulate order processing logic on affected e-commerce sites. There is no confidentiality or availability impact reported; the scope is limited to data integrity within the WooCommerce order management system (Wordfence, Red Hat CVE).

Exploitability

No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.051%, indicating a low probability of exploitation in the near term. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability was assigned by Wordfence and is tracked under GHSA-8v46-f2rh-pfmp (Wordfence).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites using the Aplazo Payment Gateway plugin (versions ≤ 1.4.3) via passive scanning tools (e.g., WPScan) or by checking publicly accessible plugin metadata.
  2. Identify the vulnerable endpoint: Locate the HTTP endpoint or WordPress action hook that triggers the check_success_response() function in class-aplazo-module.php, typically a WooCommerce payment callback URL registered by the plugin.
  3. Craft unauthenticated request: Send an HTTP POST request to the identified endpoint without any authentication credentials or capability tokens, supplying a target WooCommerce order ID in the request parameters.
  4. Manipulate order status: The missing capability check allows the function to execute, setting the specified order's status to pending payment regardless of its actual payment state, potentially disrupting order fulfillment (Wordfence, WordPress Trac).

Indicators of compromise

  • Network: Unexpected unauthenticated HTTP POST requests to WooCommerce payment callback endpoints associated with the Aplazo Payment Gateway plugin (e.g., URLs containing aplazo or check_success_response patterns) from unknown or suspicious IP addresses.
  • Logs: WordPress/WooCommerce access logs showing repeated requests to the Aplazo callback endpoint without valid session cookies or authentication headers; WooCommerce order logs showing orders unexpectedly reverted to pending payment status.
  • Application: Unusual bulk changes to WooCommerce order statuses (multiple orders set to pending payment) without corresponding customer or admin actions in the audit trail.

Mitigation and workarounds

Users should update the Aplazo Payment Gateway plugin to a version beyond 1.4.3, which includes the fix adding proper capability checks to the check_success_response() function. The patch can be reviewed in the WordPress plugin repository changeset (WordPress Changeset). As a temporary workaround, site administrators may consider disabling the plugin until an update is applied, or restricting access to the payment callback endpoint via web application firewall (WAF) rules (Wordfence).

Community reactions

The vulnerability was discovered and disclosed by Wordfence, which published the initial advisory on January 14, 2026. Coverage has been limited to automated vulnerability tracking platforms such as VulDB, Vulners, and INCIBE-CERT, with no notable independent researcher commentary or significant media coverage identified (Red Hat CVE).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management