iPOSpays Gateways WC <= 1.3.7 - Unauthenticated Missing Authorization to Settings Update via REST API Endpoint
mediumThe iPOSpays Gateways WC plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.3.7. This is due to the plugin exposing a REST API endpoint /wp-json/ipospays/v1/save_settings with 'permission_callback' set to '__return_true', which allows unauthenticated access without any capabil...
- CVSS:
- 5.3
- Affected:
- up to 1.3.7
- Fixed in:
- 1.3.8
- Disclosed:
- Feb 7, 2026