PT-2026-5090 · WordPress · Rupantorpay
CVE-2025-15511
·
Publicado
2026-01-28
·
Atualizado
2026-01-28
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Rupantorpay plugin for WordPress versions through 2.0.0
Description
The Rupantorpay plugin for WordPress is susceptible to unauthorized data modification. This is due to a missing capability check within the
handle webhook() function. An unauthenticated attacker can exploit this to modify WooCommerce order statuses by sending specifically crafted requests to the WooCommerce API endpoint. The vulnerable function is handle webhook().Recommendations
Update the Rupantorpay plugin to a version newer than 2.0.0.
Correção
Missing Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Rupantorpay