The OpenPix for WooCommerce WordPress plugin through 2.13.3 allows any authenticated user to trigger AJAX actions that reset payment gateway configuration options without capability or nonce checks. This permits any authenticated users, such as subscribers to clear API credentials and webhook status, causing persistent disruption of OpenPix payment functionality.
Metrics
Affected Vendors & Products
References
History
Thu, 02 Apr 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Pix para Woocommerce WordPress plugin through 2.13.3 allows any authenticated user to trigger AJAX actions that reset payment gateway configuration options without capability or nonce checks. This permits any authenticated users, such as subscribers to clear API credentials and webhook status, causing persistent disruption of OpenPix payment functionality. | The OpenPix for WooCommerce WordPress plugin through 2.13.3 allows any authenticated user to trigger AJAX actions that reset payment gateway configuration options without capability or nonce checks. This permits any authenticated users, such as subscribers to clear API credentials and webhook status, causing persistent disruption of OpenPix payment functionality. |
Wed, 11 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openpix
Openpix pix Para Woocommerce Wordpress Wordpress wordpress |
|
| Vendors & Products |
Openpix
Openpix pix Para Woocommerce Wordpress Wordpress wordpress |
Wed, 11 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-862 | |
| Metrics |
cvssV3_1
|
Wed, 11 Feb 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Pix para Woocommerce WordPress plugin through 2.13.3 allows any authenticated user to trigger AJAX actions that reset payment gateway configuration options without capability or nonce checks. This permits any authenticated users, such as subscribers to clear API credentials and webhook status, causing persistent disruption of OpenPix payment functionality. | |
| Title | OpenPix <= 2.13.3 - Subscriber+ Payment Gateway Settings Reset | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-04-02T12:39:55.373Z
Reserved: 2025-12-31T14:58:36.688Z
Link: CVE-2025-15400
Updated: 2026-02-11T15:57:29.804Z
Status : Awaiting Analysis
Published: 2026-02-11T06:15:47.870
Modified: 2026-04-02T13:16:23.773
Link: CVE-2025-15400
No data.
OpenCVE Enrichment
Updated: 2026-02-11T21:46:11Z