CVE-2026-12973

The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to disclose the secret order key of arbitrary WooCommerce orders and, under some configurations, to modify order statuses.
Configurations

No configuration.

History

No history.

Information

Published : 2026-07-20 07:16

Updated : 2026-07-21 18:51


NVD link : CVE-2026-12973

Mitre link : CVE-2026-12973

CVE.ORG link : CVE-2026-12973


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization