Retour à la veille

CVE-2026-104118

Publié : 4 octobre 2026
Modifié : 4 octobre 2026
Lien officiel NVD

Description détaillée

The Razorpay for WooCommerce WordPress plugin before 4.8.8 does not perform ownership or authorization checks on a REST API route used during checkout, allowing unauthenticated attackers to modify the shipping information stored on arbitrary orders.

Références et Patchs