cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forphonepe-payment-solutions phonepe-payment-solutions

Direction: ascending
Jun 07, 2024

PhonePe Payment Solutions # CVE-2022-45835

CVE, Research URL

CVE-2022-45835

Date
Nov 13, 2023
Research Description
Server-Side Request Forgery (SSRF) vulnerability in PhonePe PhonePe Payment Solutions.This issue affects PhonePe Payment Solutions: from n/a through 1.0.15.
Affected versions
max 2.0.0.
Status
vulnerable
Jul 19, 2026

PhonePe Payment Solutions # CVE-2026-11575

CVE, Research URL

CVE-2026-11575

Date
Jul 17, 2026
Research Description
The PhonePe Payment Solutions WordPress plugin before 3.1.0 does not properly verify the authenticity of incoming payment callbacks: the secret used to validate the callback signature is empty on sites configured through the current setup flow, so the expected signature reduces to an unkeyed hash of the request body that anyone can compute. This allows unauthenticated attackers to forge a payment-success notification and mark unpaid WooCommerce orders as paid without any payment being made.
Affected versions
max 3.1.0.
Status
vulnerable