
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-15512 is a Missing Authorization vulnerability in the Aplazo Payment Gateway plugin for WordPress, allowing unauthenticated attackers to modify WooCommerce order statuses. The flaw exists in all versions up to and including 1.4.3 of the plugin, due to a missing capability check on the check_success_response() function. It was initially disclosed on January 14, 2026, with the affected version range later updated to include 1.4.3 on April 8, 2026. It carries a CVSS v3.1 base score of 5.3 (Medium), assigned by Wordfence (Wordfence, Red Hat CVE).
The root cause is CWE-862 (Missing Authorization): the check_success_response() function in class-aplazo-module.php (line 206) does not perform any capability or authentication check before processing requests (WordPress Trac). Because this function is accessible over the network without any privilege requirements, an unauthenticated remote attacker can invoke it directly via an HTTP request. The attack vector is network-based, requires no user interaction, and has low attack complexity, making it trivially exploitable against any site running the vulnerable plugin versions (Wordfence).
Successful exploitation allows any unauthenticated attacker to set any WooCommerce order to pending payment status, regardless of its actual payment state. This integrity impact could be abused to disrupt order fulfillment workflows, cause financial discrepancies, or potentially manipulate order processing logic on affected e-commerce sites. There is no confidentiality or availability impact reported; the scope is limited to data integrity within the WooCommerce order management system (Wordfence, Red Hat CVE).
No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.051%, indicating a low probability of exploitation in the near term. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability was assigned by Wordfence and is tracked under GHSA-8v46-f2rh-pfmp (Wordfence).
check_success_response() function in class-aplazo-module.php, typically a WooCommerce payment callback URL registered by the plugin.pending payment regardless of its actual payment state, potentially disrupting order fulfillment (Wordfence, WordPress Trac).aplazo or check_success_response patterns) from unknown or suspicious IP addresses.pending payment status.pending payment) without corresponding customer or admin actions in the audit trail.Users should update the Aplazo Payment Gateway plugin to a version beyond 1.4.3, which includes the fix adding proper capability checks to the check_success_response() function. The patch can be reviewed in the WordPress plugin repository changeset (WordPress Changeset). As a temporary workaround, site administrators may consider disabling the plugin until an update is applied, or restricting access to the payment callback endpoint via web application firewall (WAF) rules (Wordfence).
The vulnerability was discovered and disclosed by Wordfence, which published the initial advisory on January 14, 2026. Coverage has been limited to automated vulnerability tracking platforms such as VulDB, Vulners, and INCIBE-CERT, with no notable independent researcher commentary or significant media coverage identified (Red Hat CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."