CVE-2026-12972
PayPlus Payment Gateway < 8.2.2 - Unauthenticated Order Payment Metadata Tampering
CVSS Score
5.3
EPSS Score
0.1%
EPSS Percentile
3th
The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to tamper with the payment-related metadata of arbitrary WooCommerce orders.
| Vendor | unknown |
| Product | payplus payment gateway |
| Published | Jul 20, 2026 |
| Last Updated | Jul 20, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown payplus payment gateway
Be the first to know when new medium vulnerabilities affecting unknown payplus payment gateway are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / PayPlus Payment Gateway
0 < 8.2.2
References
Credits
Pedro Pinho WPScan