CyberRota Analysis
AI-GeneratedThe ePayco Payment Gateway for WooCommerce plugin prior to version 8.4.7 is vulnerable due to inadequate verification of payment confirmation requests, enabling unauthenticated attackers to falsely mark orders as paid. This could lead to financial losses and fraud for online merchants using this plugin. WordPress site administrators utilizing this plugin should prioritize updating to the latest version to mitigate potential exploitation.
Original NVD Description
The ePayco Payment Gateway for WooCommerce WordPress plugin before 8.4.7 does not properly verify the authenticity of payment confirmation requests, allowing unauthenticated attackers to mark orders as paid without a valid gateway signature.