Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wqwq-hmg7-q93r

Опубликовано: 14 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.2 does not verify that a payment-confirmation request originates from the owner of the targeted order, nor that any payment actually occurred, allowing unauthenticated attackers to mark arbitrary orders as confirmed and, in a non-default configuration, paid.

The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.2 does not verify that a payment-confirmation request originates from the owner of the targeted order, nor that any payment actually occurred, allowing unauthenticated attackers to mark arbitrary orders as confirmed and, in a non-default configuration, paid.

EPSS

Процентиль: 13%
0.00221
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 5.9
nvd
5 дней назад

The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.2 does not verify that a payment-confirmation request originates from the owner of the targeted order, nor that any payment actually occurred, allowing unauthenticated attackers to mark arbitrary orders as confirmed and, in a non-default configuration, paid.

EPSS

Процентиль: 13%
0.00221
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-287