VYPR
Medium severity4.3NVD Advisory· Published Sep 5, 2025· Updated Apr 23, 2026

CVE-2025-58795

CVE-2025-58795

Description

Missing Authorization vulnerability in Payoneer Checkout Payoneer Checkout payoneer-checkout allows Content Spoofing.This issue affects Payoneer Checkout: from n/a through <= 3.4.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing authorization in Payoneer Checkout plugin for WordPress allows content spoofing, enabling attackers to inject malicious content or phishing pages.

The Payoneer Checkout plugin for WordPress versions up to and including 3.4.0 suffers from a missing authorization vulnerability that leads to content spoofing. The root cause is insufficient access controls, allowing unauthorized modification of page or post content without proper validation [1].

Exploitation requires a privileged user to perform an action, such as clicking a malicious link or visiting a crafted page. This means an attacker must first trick an authenticated user with sufficient privileges into interacting with a specially crafted request [1].

Successful exploitation enables an attacker to inject arbitrary content into the website's pages and posts. This can be abused to display misleading information or, more critically, to inject phishing pages that steal credentials or other sensitive data from visitors [1].

The vulnerability is addressed in version 3.5.0 of the plugin. Users are strongly advised to update immediately. Patchstack users can enable auto-updates for vulnerable plugins. While the CVSS score is 4.3 (Medium), the vendor notes low likelihood of exploitation, but content spoofing can still be leveraged in mass-exploit campaigns [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.