CVE-2026-13692
Description
The PayU CommercePro Plugin WordPress plugin through 3.8.9 does not verify the payment-gateway signature before applying order modifications, allowing unauthenticated attackers to tamper with the totals, shipping and metadata of arbitrary WooCommerce orders.
Metadata
Severity & Metrics
No CVSS data available.
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Unknown | PayU CommercePro Plugin | — | 0 ≤ 3.8.9 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| — | cna | CWE-862 Missing Authorization |