CVE-2026-10599 HIGH

CVE-2026-10599: Integrate PhonePe with WooCommerce <= 1.2.1 - Unauthenticated Payment Bypass via Transaction ID Reuse

Vendor Unknown
Product Integrate PhonePe with WooCommerce
Published August 6, 2026
Last update August 6, 2026

CVSS base score

7.5/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

What the vulnerability does

01Description

The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not validate that a verified payment transaction belongs to the order being marked as paid, nor does it verify the authenticity of its payment-completion request, allowing unauthenticated attackers to reuse a single valid transaction to mark arbitrary orders as paid and bypass payment.

Explanation of Vulnerability in Simple Terms

02Summary

A vulnerability in the Integrate PhonePe with WooCommerce plugin allows attackers to modify transaction data without authentication. The flaw affects versions up to 1.2.1 and requires no user interaction. Site owners should update immediately to prevent unauthorized payment manipulation.

What an attacker can do

03Attacker Capabilities

Modify payment transaction data or order information without logging in.

Potential impact on your site

04Site Impact

Attackers can alter payment records, order amounts, or transaction status without authorization.

Conditions required to exploit

05Prerequisites

Network access to the site; no authentication or user interaction required.

Key dates

06Disclosure timeline

August 6, 2026 CVE published