WordPress · Razorpay Payment Links For Woocommerce · CVE-2026-97299
**Name of the Vulnerable Software and Affected Versions**
Razorpay Payment Links for WooCommerce versions prior to 2.1.6
**Description**
An unauthenticated Cross Site Request Forgery (CSRF) issue exists in the plugin. CSRF is a type of attack that tricks a victim into submitting a malicious request. It occurs when a web application performs an action without verifying that the user intended to perform that action.
**Recommendations**
Update Razorpay Payment Links for WooCommerce to version 2.1.6 or later.