Beveiligingsadvies

CVE-2026-12973

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-07-20 06:00:04
Laatst bijgewerkt 2026-07-20 14:59:50
Toegewezen door WPScan
CVSS-score 6.5
Status PUBLISHED

Beschrijving

The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to disclose the secret order key of arbitrary WooCommerce orders and, under some configurations, to modify order statuses.