MEDIUM
CVE-2026-56023
CVSS
5.4
Description
Customer Broken Access Control in UPI QR Code Payment Gateway for WooCommerce <= 1.6.2 versions.
Summary dbcve.org
Broken Access Control vulnerability in the UPI QR Code Payment Gateway WooCommerce plugin versions 1.6.2 and below allows customers to bypass proper authorization checks, potentially accessing or manipulating payment data or administrative functions they should not have access to.
Mitigation
Update to a version newer than 1.6.2 if available, or implement proper role-based access control checks and authorization validation on all sensitive endpoints within the plugin.
Weakness (CWE)
CWE-862
Missing Authorization
EPSS Score
0.29%
Probability of exploitation in next 30 days
21.5th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.