CyberRota
← Ana sayfaya dön

CVE-2026-12972

MEDIUM · CVSS 5.3 EPSS %0.13

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-07-20T07:16:35.290 · Çekilme zamanı: 2026-07-21T06:06:23.094415+00:00

CyberRota Yorumu

Saldırganın giriş yapmış olması gerekebilir.

CVE
CVE-2026-12972
Severity
MEDIUM
CVSS
5.3
EPSS
%0.13
WordPress

Orijinal NVD Açıklaması

The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to tamper with the payment-related metadata of arbitrary WooCommerce orders.