AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-10599

HIGH · CVSS 7.5 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Integrate PhonePe with WooCommerce plugin for WordPress versions up to 1.2.1 is vulnerable due to inadequate validation of payment transactions, allowing attackers to exploit this flaw to mark any order as paid without proper authorization. This could lead to significant financial losses and fraud for online merchants. WordPress site administrators using this plugin should prioritize patching to mitigate the risk of unauthorized payment processing.

CVE
CVE-2026-10599
Severity
HIGH
CVSS
7.5
EPSS
0.16%
WordPress

Original NVD Description

The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not validate that a verified payment transaction belongs to the order being marked as paid, nor does it verify the authenticity of its payment-completion request, allowing unauthenticated attackers to reuse a single valid transaction to mark arbitrary orders as paid and bypass payment.