The Pix para Woocommerce WordPress plugin through 2.13.3 allows any authenticated user to trigger AJAX actions that reset payment gateway configuration options without capability or nonce checks. This permits any authenticated users, such as subscribers to clear API credentials and webhook status, causing persistent disruption of OpenPix payment functionality.
Metrics
Affected Vendors & Products
References
History
Wed, 11 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openpix
Openpix pix Para Woocommerce Wordpress Wordpress wordpress |
|
| Vendors & Products |
Openpix
Openpix pix Para Woocommerce Wordpress Wordpress wordpress |
Wed, 11 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-862 | |
| Metrics |
cvssV3_1
|
Wed, 11 Feb 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Pix para Woocommerce WordPress plugin through 2.13.3 allows any authenticated user to trigger AJAX actions that reset payment gateway configuration options without capability or nonce checks. This permits any authenticated users, such as subscribers to clear API credentials and webhook status, causing persistent disruption of OpenPix payment functionality. | |
| Title | OpenPix <= 2.13.3 - Subscriber+ Payment Gateway Settings Reset | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-02-11T16:01:40.892Z
Reserved: 2025-12-31T14:58:36.688Z
Link: CVE-2025-15400
Updated: 2026-02-11T15:57:29.804Z
Status : Awaiting Analysis
Published: 2026-02-11T06:15:47.870
Modified: 2026-02-11T17:16:07.057
Link: CVE-2025-15400
No data.
OpenCVE Enrichment
Updated: 2026-02-11T21:46:11Z