← WordPress Vulnerabilities
WordPress security by component

Direct Payments for WooCommerce

Direct Payments for WooCommerce is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 01, 2026; an upstream CVSS base score is still pending.

Plugin slug: direct-payments-for-woocommerce

CVE-2026-12966: Direct Payments lets visitors forge payment state and proof on other orders

Direct Payments for WooCommerce before 2.5.3 exposes several unauthenticated AJAX handlers that modify a selected order without confirming that the requester owns it. A visitor can target another customer's WooCommerce order, mark it as payment sent, overwrite the payment-method label and attach a forged payment-proof file. The published record does not disclose the action names, order identifier, status and label fields, upload parameter or update functions.

PublishedAug 01, 2026
Known safe version2.5.3
Safe version
Aug 01, 2026 CVE-2026-12966
Direct Payments lets visitors forge payment state and proof on other orders
Direct Payments for WooCommerce before 2.5.3 exposes several unauthenticated AJAX handlers that modify a selected order without confirming that the requester owns it. A visitor can target another customer's WooCommerce order, mark it as payment sent, overwrite the payment-method label and attach a forged payment-proof file. The published record does not disclose the action names, order identifier, status and label fields, upload parameter or update functions.
2.5.3
CVEPending
NVDPending