What the vulnerability does
01Description
The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not validate that a verified payment transaction belongs to the order being marked as paid, nor does it verify the authenticity of its payment-completion request, allowing unauthenticated attackers to reuse a single valid transaction to mark arbitrary orders as paid and bypass payment.
Explanation of Vulnerability in Simple Terms
02Summary
A vulnerability in the Integrate PhonePe with WooCommerce plugin allows attackers to modify transaction data without authentication. The flaw affects versions up to 1.2.1 and requires no user interaction. Site owners should update immediately to prevent unauthorized payment manipulation.
What an attacker can do
03Attacker Capabilities
Modify payment transaction data or order information without logging in.
Potential impact on your site
04Site Impact
Attackers can alter payment records, order amounts, or transaction status without authorization.
Conditions required to exploit
05Prerequisites
Network access to the site; no authentication or user interaction required.
Key dates
06Disclosure timeline
August 6, 2026
CVE published