CVE-2026-104118
Razorpay for WooCommerce < 4.8.8 - Unauthenticated Order Shipping Modification via IDOR
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Razorpay for WooCommerce WordPress plugin before 4.8.8 does not perform ownership or authorization checks on a REST API route used during checkout, allowing unauthenticated attackers to modify the shipping information stored on arbitrary orders.
| Vendor | unknown |
| Product | razorpay for woocommerce |
| Published | Oct 4, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown razorpay for woocommerce
Be the first to know when new unknown vulnerabilities affecting unknown razorpay for woocommerce are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Razorpay for WooCommerce
0 < 4.8.8
References
Credits
Charles Vosburgh WPScan