VYPR

Direct Payments for WooCommerce

by WordPress

CVEs (1)

  • CVE-2026-12966Aug 1, 2026
    risk 0.00cvss epss 0.00

    The Direct Payments for WooCommerce WordPress plugin before 2.5.3 does not verify that the requester owns the targeted WooCommerce order in several unauthenticated AJAX handlers before changing its status and overwriting its payment metadata, allowing unauthenticated attackers…