ePayco plugin for WooCommerce, CVE-2026-84043
- CVE, Research URL
- Home page URL
- Application
- Published on
- Sep 04, 2026
- Research Description
- The ePayco Payment Gateway for WooCommerce WordPress plugin before 8.4.7 does not properly verify the authenticity of payment confirmation requests, allowing unauthenticated attackers to mark orders as paid without a valid gateway signature.
- Affected versions
-
max 8.4.7.
- Status
-
vulnerable
| Previous vulnerability researches |
|---|
| ePayco plugin for WooCommerce (CVE-2026-78260) , Aug 29, 2026 |
| ePayco plugin for WooCommerce (CVE-2026-84043) , Sep 06, 2026 |