cleantalk
Vulnerabilities and Security Researches

Eupago Gateway For Woocommerce, CVE-2026-7862

CVE, Research URL

CVE-2026-7862

Published on
May 28, 2026
Research Description
The Eupago Gateway For Woocommerce WordPress plugin before 4.7.2 does not properly restrict access to its refund request handler, allowing unauthenticated attackers to initiate refunds against any WooCommerce order using the merchant's payment gateway credentials, and for applicable payment methods, to redirect refunded funds to an attacker-controlled bank account.
Affected versions
max 4.7.2.
Status
vulnerable