ZeroHour

CVE-2026-84043

CVSS 3.1
5.3 medium
EPSS
<1%p2
Published
()
Modified
Description

The ePayco Payment Gateway for WooCommerce WordPress plugin before 8.4.7 does not properly verify the authenticity of payment confirmation requests, allowing unauthenticated attackers to mark orders as paid without a valid gateway signature.

Ecosystems
WordPress, E-commerce
Weakness
CWE-345
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.