AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-16739

UNKNOWN · CVSS N/A

Source: NVD + CISA KEV + EPSS · Published 2026-08-14 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

The Epeken All Kurir for WooCommerce plugin for WordPress versions up to 2.1.2 is vulnerable due to a lack of verification for payment-confirmation requests, enabling unauthenticated attackers to falsely mark any order as confirmed and potentially paid. This could lead to significant financial losses and order management issues for affected e-commerce sites. WordPress site administrators using this plugin should prioritize immediate updates or mitigations to protect against unauthorized order manipulations.

CVE
CVE-2026-16739
Severity
UNKNOWN
CVSS
N/A
EPSS
N/A
WordPress

Original NVD Description

The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.2 does not verify that a payment-confirmation request originates from the owner of the targeted order, nor that any payment actually occurred, allowing unauthenticated attackers to mark arbitrary orders as confirmed and, in a non-default configuration, paid.