WordPress · Tamara Checkout · CVE-2026-16962
**Name of the Vulnerable Software and Affected Versions**
Tamara Checkout versions prior to 1.9.9.21
**Description**
The plugin fails to verify the order key, a nonce, or any specific capability on its public payment cancel and fail return URLs. This allows an unauthenticated attacker to change the status of any WooCommerce order by providing a numeric order id. By enumerating these ids, an attacker can cancel or fail arbitrary orders across the store, which triggers side-effects such as stock release and notifications.
**Recommendations**
Update the plugin to a version newer than 1.9.9.20.