The Razorpay for WooCommerce WordPress plugin before 4.8.8 does not perform ownership or authorization checks on a REST API route used during checkout, allowing unauthenticated attackers to modify the shipping information stored on arbitrary orders.
CVE-2026-104118
NONE
Updated Oct 04, 2026
Unknown
unknown:razorpay for woocommerce
CVE Details
CVE ID
CVE-2026-104118
Published Date
Oct 04, 2026
Vendor
Unknown
Severity
NONE
Impact
Minimal impact
Source
View Advisory