← WordPress Vulnerabilities
WordPress security by component

Buckaroo Woocommerce Payments Plugin

Buckaroo Woocommerce Payments Plugin is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 01, 2026; an upstream CVSS base score is still pending.

Plugin slug: buckaroo-woocommerce-payments-plugin

CVE-2026-13329: Buckaroo lets Subscribers trigger captured-order refunds

Buckaroo Woocommerce Payments Plugin before 4.9.0 exposes a payment-capture refund AJAX action without a capability check or nonce validation. Any authenticated Subscriber-or-higher user can select a captured WooCommerce order and trigger a refund through the site's payment integration. The published record does not disclose the AJAX action, order or transaction parameter, callback, refund amount behavior or processor method.

PublishedAug 01, 2026
Known safe version4.9.0
Safe version
Aug 01, 2026 CVE-2026-13329
Buckaroo lets Subscribers trigger captured-order refunds
Buckaroo Woocommerce Payments Plugin before 4.9.0 exposes a payment-capture refund AJAX action without a capability check or nonce validation. Any authenticated Subscriber-or-higher user can select a captured WooCommerce order and trigger a refund through the site's payment integration. The published record does not disclose the AJAX action, order or transaction parameter, callback, refund amount behavior or processor method.
4.9.0
CVEPending
NVDPending