CyberRota Analysis
AI-GeneratedThe Epeken All Kurir for WooCommerce plugin for WordPress versions up to 2.1.2 is vulnerable due to a lack of verification for payment-confirmation requests, enabling unauthenticated attackers to falsely mark any order as confirmed and potentially paid. This could lead to significant financial losses and order management issues for affected e-commerce sites. WordPress site administrators using this plugin should prioritize immediate updates or mitigations to protect against unauthorized order manipulations.
Original NVD Description
The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.2 does not verify that a payment-confirmation request originates from the owner of the targeted order, nor that any payment actually occurred, allowing unauthenticated attackers to mark arbitrary orders as confirmed and, in a non-default configuration, paid.