CVE-2026-104118

Summary

The Razorpay for WooCommerce WordPress plugin before 4.8.8 does not perform ownership or authorization checks on a REST API route used during checkout, allowing unauthenticated attackers to modify the shipping information stored on arbitrary orders.

Affected Software

VendorProductVersion RangeStatus
UnknownRazorpay for WooCommerce0 < 4.8.8affected

Weaknesses

  • CWE-639 Authorization Bypass Through User-Controlled Key

References