CVE-2026-7862
Description
The Eupago Gateway For Woocommerce WordPress plugin before 4.7.2 does not properly restrict access to its refund request handler, allowing unauthenticated attackers to initiate refunds against any WooCommerce order using the merchant's payment gateway credentials, and for applicable payment methods, to redirect refunded funds to an attacker-controlled bank account.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
The Eupago Gateway For Woocommerce plugin before 4.7.2 contains an unauthenticated refund initiation vulnerability allowing attackers to drain merchant funds.
Vulnerability
The Eupago Gateway For Woocommerce WordPress plugin versions before 4.7.2 fails to properly restrict access to its refund request handler. This allows any unauthenticated visitor to trigger a refund against any WooCommerce order without the merchant's authorization, using the merchant's stored payment gateway credentials. The vulnerability is present in all plugin versions prior to the 4.7.2 release [1].
Exploitation
An unauthenticated attacker needs only network access to a WooCommerce site running the vulnerable plugin. No authentication or prior access is required. The attacker can send a crafted request to the refund handler endpoint, specifying any existing WooCommerce order ID. For payment methods that support refund redirection, the attacker can also specify an attacker-controlled bank account to receive the refunded funds [1].
Impact
Successful exploitation allows an unauthenticated attacker to drain merchant funds by initiating fraudulent refunds. For supported payment methods, the funds can be redirected to an attacker-controlled bank account, resulting in direct financial loss. The attacker can target any order in the WooCommerce system, regardless of its original payer or status [1].
Mitigation
The vulnerability is fixed in version 4.7.2 of the plugin, released on or around 2026-05-07. All users should update to this version or later immediately. As of the publication date, there is no known workaround for sites that cannot upgrade. The vulnerability is publicly disclosed and has been added to the WPScan vulnerability database [1].
AI Insight generated on May 28, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2<4.7.2+ 1 more
- (no CPE)range: <4.7.2
- (no CPE)range: <4.7.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.