WordPress security by component
Buckaroo Woocommerce Payments Plugin
Plugin description
Buckaroo Woocommerce Payments Plugin is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 01, 2026; an upstream CVSS base score is still pending.
Plugin slug:
buckaroo-woocommerce-payments-pluginLatest vulnerability
CVE-2026-13329: Buckaroo lets Subscribers trigger captured-order refunds
Buckaroo Woocommerce Payments Plugin before 4.9.0 exposes a payment-capture refund AJAX action without a capability check or nonce validation. Any authenticated Subscriber-or-higher user can select a captured WooCommerce order and trigger a refund through the site's payment integration. The published record does not disclose the AJAX action, order or transaction parameter, callback, refund amount behavior or processor method.
| Safe version |
|
||
|---|---|---|---|
| Aug 01, 2026 |
CVE-2026-13329
Buckaroo lets Subscribers trigger captured-order refunds
Buckaroo Woocommerce Payments Plugin before 4.9.0 exposes a payment-capture refund AJAX action without a capability check or nonce validation. Any authenticated Subscriber-or-higher user can select a captured WooCommerce order and trigger a refund through the site's payment integration. The published record does not disclose the AJAX action, order or transaction parameter, callback, refund amount behavior or processor method.
|
4.9.0 |
CVEPending
NVDPending
|