CyberRota Analysis
AI-GeneratedThe PayU CommercePro Plugin for WordPress versions up to 3.8.9 is vulnerable due to a lack of signature verification for payment-gateway transactions, enabling unauthenticated attackers to manipulate order totals, shipping details, and metadata in WooCommerce. This flaw poses a risk of financial fraud and data integrity issues for e-commerce operations. WordPress site administrators using this plugin should prioritize patching to mitigate potential exploitation.
Original NVD Description
The PayU CommercePro Plugin WordPress plugin before 3.9.0 does not verify the payment-gateway signature before applying order modifications, allowing unauthenticated attackers to tamper with the totals, shipping and metadata of arbitrary WooCommerce orders.