CVE-2025-14460 | Piraeus Bank WooCommerce Payment Gateway Plugin up to 3.1.4 on WordPress API Endpoint MerchantReference authorization
A vulnerability was found in Piraeus Bank WooCommerce Payment Gateway Plugin up to 3.1.4 on WordPress. It has been classified as critical. This issue affects some unknown processing of the component API Endpoint. The manipulation of the argument MerchantReference leads to missing authorization.
This vulnerability is uniquely identified as CVE-2025-14460. The attack is possible to be carried out remotely. No exploit exists.