CVE-2026-84043CWE-345

CVE-2026-84043

Medium · published September 4, 2026

CVSS v3.1
5.3
EPSS
0%
Percentile
1.7
In the wild
Unconfirmed
What it is

The ePayco Payment Gateway for WooCommerce WordPress plugin before 8.4.7 does not properly verify the authenticity of payment confirmation requests, allowing unauthenticated attackers to mark orders as paid without a valid gateway signature.

The record
Technical detail
CVSS v3.1
5.3 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.00114 · 1.7th percentile
Weakness
CWE-345 · Insufficient Verification of Data Authenticity
Published
2026-09-04T14:17Z
References (1)
EPSS history
Timeline
  • 05 SEP 03:44Z
    EPSS moved — → 0%
    epss
  • 04 SEP 10:00Z
    ePayco Payment Gateway for WooCommerce < 8.4.7 - Unauthenticated Payment Confirmation Bypass
    cvelistv5