PT-2026-67023 · WordPress · Direct Payments For Woocommerce

·

CVE-2026-12966

·

Published

2026-08-01

·

Updated

2026-08-01

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Direct Payments for WooCommerce versions prior to 2.5.3
Description Several unauthenticated AJAX handlers fail to verify if the requester owns the targeted WooCommerce order before modifying its status and overwriting payment metadata. This allows unauthenticated attackers to tamper with orders belonging to other customers, which includes forging a payment sent state, overwriting the payment-method label, and attaching forged payment-proof files.
Recommendations Update Direct Payments for WooCommerce to version 2.5.3 or later.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12966

Affected Products

Direct Payments For Woocommerce