rootpwn

medium · CVSS v3 5.3

CVE-2026-84091

The SUMIT Payment Gateway for WooCommerce WordPress plugin before 4.0.0 does not verify with the payment provider that a…

Description

The SUMIT Payment Gateway for WooCommerce WordPress plugin before 4.0.0 does not verify with the payment provider that a payment notification is genuine before marking the corresponding order as paid, allowing unauthenticated users to mark a pending order paid without completing payment.

Scores

Severity
medium
CVSS v2
5
CVSS v3
5.3
CVSS v4
EPSS

← All CVEs