WordPress security by component
Direct Payments for WooCommerce
Plugin description
Direct Payments for WooCommerce is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 01, 2026; an upstream CVSS base score is still pending.
Plugin slug:
direct-payments-for-woocommerceLatest vulnerability
CVE-2026-12966: Direct Payments lets visitors forge payment state and proof on other orders
Direct Payments for WooCommerce before 2.5.3 exposes several unauthenticated AJAX handlers that modify a selected order without confirming that the requester owns it. A visitor can target another customer's WooCommerce order, mark it as payment sent, overwrite the payment-method label and attach a forged payment-proof file. The published record does not disclose the action names, order identifier, status and label fields, upload parameter or update functions.
| Safe version |
|
||
|---|---|---|---|
| Aug 01, 2026 |
CVE-2026-12966
Direct Payments lets visitors forge payment state and proof on other orders
Direct Payments for WooCommerce before 2.5.3 exposes several unauthenticated AJAX handlers that modify a selected order without confirming that the requester owns it. A visitor can target another customer's WooCommerce order, mark it as payment sent, overwrite the payment-method label and attach a forged payment-proof file. The published record does not disclose the action names, order identifier, status and label fields, upload parameter or update functions.
|
2.5.3 |
CVEPending
NVDPending
|