CVE-2026-10599

Summary

The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not validate that a verified payment transaction belongs to the order being marked as paid, nor does it verify the authenticity of its payment-completion request, allowing unauthenticated attackers to reuse a single valid transaction to mark arbitrary orders as paid and bypass payment.

Affected Software

VendorProductVersion RangeStatus
UnknownIntegrate PhonePe with WooCommerce0 <= 1.2.1affected

Weaknesses

  • CWE-639 Authorization Bypass Through User-Controlled Key
  • CWE-345 Insufficient Verification of Data Authenticity

References