CVE-2026-84043CWE-345
CVE-2026-84043
Medium · published September 4, 2026
What it is
The ePayco Payment Gateway for WooCommerce WordPress plugin before 8.4.7 does not properly verify the authenticity of payment confirmation requests, allowing unauthenticated attackers to mark orders as paid without a valid gateway signature.
The record
Technical detail
- CVSS v3.1
- 5.3 · MEDIUM
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- CVSS v4.0
- Not supplied
- EPSS
- 0.00114 · 1.7th percentile
- Weakness
- CWE-345 · Insufficient Verification of Data Authenticity
- Published
- 2026-09-04T14:17Z
References (1)
EPSS history
Timeline