Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-10599

Опубликовано: 06 авг. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not validate that a verified payment transaction belongs to the order being marked as paid, nor does it verify the authenticity of its payment-completion request, allowing unauthenticated attackers to reuse a single valid transaction to mark arbitrary orders as paid and bypass payment.

EPSS

Процентиль: 6%
0.0016
Низкий

7.5 High

CVSS3

Дефекты

CWE-345

Связанные уязвимости

CVSS3: 7.5
github
12 дней назад

The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not validate that a verified payment transaction belongs to the order being marked as paid, nor does it verify the authenticity of its payment-completion request, allowing unauthenticated attackers to reuse a single valid transaction to mark arbitrary orders as paid and bypass payment.

EPSS

Процентиль: 6%
0.0016
Низкий

7.5 High

CVSS3

Дефекты

CWE-345