The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not validate that a verified payment transaction belongs to the order being marked as paid, nor does it verify the authenticity of its payment-completion request, allowing unauthenticated attackers to reuse a single valid transaction to mark arbitrary orders as paid and bypass payment.
Metrics
Affected Vendors & Products
References
History
Fri, 07 Aug 2026 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-285 CWE-287 |
Thu, 06 Aug 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not validate that a verified payment transaction belongs to the order being marked as paid, nor does it verify the authenticity of its payment-completion request, allowing unauthenticated attackers to reuse a single valid transaction to mark arbitrary orders as paid and bypass payment. | |
| Title | Integrate PhonePe with WooCommerce <= 1.2.1 - Unauthenticated Payment Bypass via Transaction ID Reuse | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-06T16:45:21.571Z
Reserved: 2026-06-02T08:31:09.956Z
Link: CVE-2026-10599
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-07T01:15:05Z