Medium severity5.3NVD Advisory· Published Sep 23, 2026
CVE-2026-84091
CVE-2026-84091
Description
The SUMIT Payment Gateway for WooCommerce WordPress plugin before 4.0.0 does not verify with the payment provider that a payment notification is genuine before marking the corresponding order as paid, allowing unauthenticated users to mark a pending order paid without completing payment.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <4.0.0
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.