Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x972-w82m-gqc5

Опубликовано: 07 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not validate that a verified payment transaction belongs to the order being marked as paid, nor does it verify the authenticity of its payment-completion request, allowing unauthenticated attackers to reuse a single valid transaction to mark arbitrary orders as paid and bypass payment.

The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not validate that a verified payment transaction belongs to the order being marked as paid, nor does it verify the authenticity of its payment-completion request, allowing unauthenticated attackers to reuse a single valid transaction to mark arbitrary orders as paid and bypass payment.

EPSS

Процентиль: 6%
0.0016
Низкий

7.5 High

CVSS3

Дефекты

CWE-345

Связанные уязвимости

CVSS3: 7.5
nvd
12 дней назад

The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not validate that a verified payment transaction belongs to the order being marked as paid, nor does it verify the authenticity of its payment-completion request, allowing unauthenticated attackers to reuse a single valid transaction to mark arbitrary orders as paid and bypass payment.

EPSS

Процентиль: 6%
0.0016
Низкий

7.5 High

CVSS3

Дефекты

CWE-345