SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-12972

MEDIUM · CVSS 5.3 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

The PayPlus Payment Gateway plugin for WordPress versions prior to 8.2.2 is vulnerable due to inadequate authorization and order-ownership validation in an AJAX action accessible to unauthenticated users. This flaw allows attackers to manipulate payment-related metadata for any WooCommerce order, potentially leading to unauthorized transactions or data breaches. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of exploitation.

CVE
CVE-2026-12972
Severity
MEDIUM
CVSS
5.3
EPSS
0.18%
WordPress

Original NVD Description

The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to tamper with the payment-related metadata of arbitrary WooCommerce orders.