The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.4 does not verify that a payment-confirmation request originates from the owner of the targeted order, nor that any payment actually occurred, allowing unauthenticated attackers to mark arbitrary orders as confirmed and, in a non-default configuration, paid.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-14 06:17
Updated : 2026-08-31 09:17
NVD link : CVE-2026-16739
Mitre link : CVE-2026-16739
CVE.ORG link : CVE-2026-16739
JSON object : View
Products Affected
No product.
CWE
CWE-287
Improper Authentication
