PT-2025-44941 · Beycanpress+1 · Crypto Payment Gateway With Payeer For Woocommerce

CVE-2025-11890

·

Published

2025-11-03

·

Updated

2025-11-04

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Crypto Payment Gateway with Payeer for WooCommerce versions prior to 1.0.4
Description An issue exists where the plugin fails to properly verify payment status via server-side validation. This flaw allows unauthenticated attackers to update unpaid order statuses to paid through the '/wc-api/bp-payeer-gateway-callback' endpoint, potentially leading to revenue loss.
Recommendations Update to a version later than 1.0.3. Restrict access to the '/wc-api/bp-payeer-gateway-callback' endpoint to minimize the risk of exploitation.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-11890

Affected Products

Crypto Payment Gateway With Payeer For Woocommerce