CVE-2026-6372General

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Missing Authorization vulnerability in Plisio Accept Cryptocurrencies with Plisio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accept Cryptocurrencies with Plisio: from n/a through 2.0.5.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-04-16); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-16: 1Mentions · 2026-04-22: 1Mentions · 2026-04-27: 1PoC Mentioned / Linked · 2026-04-27: 1Technical Details · 2026-04-27: 104-1604-2204-27
Signal classification2 categories
General
266.7%
PoC
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-161
General1
2026-04-221
General1
2026-04-271
PoC1
Full discourse3 posts
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-6372-plisio-payment-gateway-for-woocommerce-version-2-0-6-medium-vulnerability-proof-of-concept CVE-2026-6372 plisio-payment-gateway-for-woocommerce (CVSS Score 5.3) #WordPress plugin #vulnerability #cybersecurity #wordpressfirewall #wo…

    Post summary

    The post shares a proof‑of‑concept for CVE‑2026‑6372 affecting the Plisio payment gateway plugin for WooCommerce, detailing the medium‑severity flaw and CVSS score.

    0000052
    6 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-6372: Plisio Plugin Authorization Bypass - What It Means for Your Business and How to Respond https://hubs.li/Q04cZdVy0

    Post summary

    The brief title indicates an article about an authorization bypass in the Plisio plugin but offers no concrete details on exploitation, mitigation, or technical specifics.

    0000032
    29 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-6372 Missing Authorization vulnerability in Plisio Accept Cryptocurrencies with Plisio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue aff… https://www.cve.org/CVERecord?id=CVE-2026-6372

    Post summary

    The tweet announces CVE‑2026‑6372 as a missing authorization flaw in Plisio but provides no further technical details, PoC, or patch information.

    0000078
    57.2K followersView on X

Explore more