HIGH

CVE-2026-10599

2026-08-06 CVSS v3.1
CVSS
7.5

Description

The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not validate that a verified payment transaction belongs to the order being marked as paid, nor does it verify the authenticity of its payment-completion request, allowing unauthenticated attackers to reuse a single valid transaction to mark arbitrary orders as paid and bypass payment.

Weakness (CWE)

CWE-345
CWE-639 Authorization Bypass (IDOR)

EPSS Score

0.16%
Probability of exploitation in next 30 days
5.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE