MEDIUM

CVE-2026-56023

2026-06-25 CVSS v3.1
CVSS
5.4

Description

Customer Broken Access Control in UPI QR Code Payment Gateway for WooCommerce <= 1.6.2 versions.

Summary dbcve.org

Broken Access Control vulnerability in the UPI QR Code Payment Gateway WooCommerce plugin versions 1.6.2 and below allows customers to bypass proper authorization checks, potentially accessing or manipulating payment data or administrative functions they should not have access to.

Mitigation

Update to a version newer than 1.6.2 if available, or implement proper role-based access control checks and authorization validation on all sensitive endpoints within the plugin.

Weakness (CWE)

CWE-862 Missing Authorization

EPSS Score

0.29%
Probability of exploitation in next 30 days
21.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE