๐Ÿ” CVE Alert

CVE-2026-13692

UNKNOWN 0.0

PayU CommercePro <= 3.8.9 - Unauthenticated Order Tampering

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The PayU CommercePro Plugin WordPress plugin through 3.8.9 does not verify the payment-gateway signature before applying order modifications, allowing unauthenticated attackers to tamper with the totals, shipping and metadata of arbitrary WooCommerce orders.

Vendor unknown
Product payu commercepro plugin
Published Jul 29, 2026
Stay Ahead of the Next One

Get instant alerts for unknown payu commercepro plugin

Be the first to know when new unknown vulnerabilities affecting unknown payu commercepro plugin are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / PayU CommercePro Plugin
0 โ‰ค 3.8.9

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/e2dc15c7-2210-4be8-b7f3-55a9477e488d/

Credits

J4ck13Ch4n WPScan