CVE-2026-6372
Published: 15 April 2026
Summary
CVE-2026-6372 is a high-severity Missing Authorization (CWE-862) vulnerability. Its CVSS base score is 7.5 (High).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked at the 12.5th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified are NIST 800-53 AC-3 (Access Enforcement) and SI-2 (Flaw Remediation).
Deeper analysis
CVE-2026-6372 is a missing authorization vulnerability (CWE-862) in the Accept Cryptocurrencies with Plisio WordPress plugin, a payment gateway for WooCommerce. The flaw allows exploiting incorrectly configured access control security levels and affects all versions from n/a through 2.0.5. It has a CVSS v3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N), indicating high severity due to network accessibility, low attack complexity, and no privileges required.
Unauthenticated attackers can exploit this vulnerability remotely without user interaction. Exploitation enables high integrity impact, such as bypassing payments in the plugin's functionality.
The Patchstack advisory at https://patchstack.com/database/wordpress/plugin/plisio-payment-gateway-for-woocommerce/vulnerability/wordpress-accept-cryptocurrencies-with-plisio-plugin-2-0-5-payment-bypass-vulnerability?_s_id=cve documents this as a payment bypass vulnerability in version 2.0.5 and earlier, recommending mitigation through plugin updates to address the access control issue.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2026-22983
Vulnerability details
Missing Authorization vulnerability in Plisio Accept Cryptocurrencies with Plisio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accept Cryptocurrencies with Plisio: from n/a through 2.0.5.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
Missing authorization in public-facing WordPress/WooCommerce payment plugin enables remote unauthenticated exploitation of a public-facing application for integrity impact like payment bypass.
CVEs Like This One
Affected Assets
Mitigating Controls
Mitigating Controls (NIST 800-53 r5) AI
Enforces approved authorizations for access to system resources, directly preventing exploitation of the missing authorization vulnerability in the Plisio plugin.
Implements least privilege to restrict access to payment functions only to authorized users, mitigating unauthorized bypasses due to incorrect access control configurations.
Requires timely identification, reporting, and correction of flaws like this missing authorization vulnerability through plugin updates.