CVE-2026-13329

The Buckaroo Woocommerce Payments Plugin WordPress plugin before 4.9.0 does not perform any capability check or nonce validation on an AJAX action that processes payment capture refunds, allowing any authenticated user, including Subscribers, to trigger refunds against captured orders.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-01 07:16

Updated : 2026-08-26 16:31


NVD link : CVE-2026-13329

Mitre link : CVE-2026-13329

CVE.ORG link : CVE-2026-13329


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control