VYPR

Tamara Checkout

by WordPress

Source repositories

CVEs (2)

  • CVE-2025-23997MedJan 21, 2025
    risk 0.42cvss 6.5epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tamara Solution Tamara Checkout tamara-checkout allows Stored XSS.This issue affects Tamara Checkout: from n/a through < 1.9.9.1.

  • CVE-2026-16962MedAug 21, 2026
    risk 0.34cvss 5.3epss 0.00

    The Tamara Checkout WordPress plugin through 1.9.9.20 does not verify the order key, a nonce, or any capability on its public payment cancel/fail return URLs, changing a WooCommerce order's status based solely on an attacker-supplied numeric order id, so an unauthenticated…