CVE-2025-62870
Description
Missing Authorization vulnerability in Eupago Eupago Gateway For Woocommerce eupago-gateway-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Eupago Gateway For Woocommerce: from n/a through <= 4.7.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Missing authorization in Eupago Gateway For Woocommerce plugin (≤4.7.1) allows attackers to exploit incorrectly configured access controls.
The Eupago Gateway For Woocommerce plugin for WordPress contains a missing authorization vulnerability, classified as a broken access control issue [1]. This means that certain functions or endpoints within the plugin do not properly verify user permissions, allowing requests to be processed without the required authentication or authorization checks.
Attackers can exploit this vulnerability by sending crafted HTTP requests to the vulnerable endpoints without needing any prior authentication. The lack of proper access control checks enables unauthenticated users to perform actions that should be restricted to higher-privileged roles, such as administrators. The reference notes that such vulnerabilities are frequently used in mass-exploit campaigns targeting thousands of websites [1].
The impact of successful exploitation can include unauthorized modification of plugin settings, access to sensitive data, or other administrative actions, depending on the specific missing authorization. The CVSS v3 base score is 5.3 (Medium), reflecting the potential for partial compromise of confidentiality or integrity [1].
As a mitigation, users should immediately update the Eupago Gateway For Woocommerce plugin to a version newer than 4.7.1, if available. The vendor has likely released a patch to address this issue. If updating is not possible, contacting the hosting provider or a web developer for assistance is recommended [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2<=4.7.1+ 1 more
- (no CPE)range: <=4.7.1
- (no CPE)range: <=4.7.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.