cleantalk
Vulnerabilities and Security Researches

ePayco plugin for WooCommerce, CVE-2026-84043

CVE, Research URL

CVE-2026-84043

Published on
Sep 04, 2026
Research Description
The ePayco Payment Gateway for WooCommerce WordPress plugin before 8.4.7 does not properly verify the authenticity of payment confirmation requests, allowing unauthenticated attackers to mark orders as paid without a valid gateway signature.
Affected versions
max 8.4.7.
Status
vulnerable