PoC Index

CVE-2025-15400

MEDIUM 6.5EPSS 0.3%

The OpenPix for WooCommerce WordPress plugin through 2.13.3 allows any authenticated user to trigger AJAX actions that reset payment gateway configuration options without capability or nonce checks. This permits any authenticated users, such as subscribers to clear API credentials and webhook status, causing persistent disruption of OpenPix payment functionality.

CVSS v3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS
0.31% chance of exploitation in the next 30 days, 23th percentile
Published
2026-02-11
Updated
2026-04-02

Proof-of-concept exploits (1)

References

Related