The zipMoney(Zip Co) Payments Plugin for WooCommerce WordPress plugin before 2.4.0 does not perform any authorisation checks on one of its front-end request handlers, and does not restrict which option name a caller may supply, allowing unauthenticated users to delete arbitrary WordPress options. This can be used to destroy site and access control configuration, deactivate every installed zipMoney(Zip Co) Payments Plugin for WooCommerce WordPress plugin before 2.4.0, and take the site offline.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-10 07:17
Updated : 2026-09-10 15:13
NVD link : CVE-2026-78361
Mitre link : CVE-2026-78361
CVE.ORG link : CVE-2026-78361
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
