CVE-2026-14830
FlxWoo < 3.1.1 - Unauthenticated Payment Bypass
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout session was actually paid before marking the associated order as paid, allowing unauthenticated attackers to complete WooCommerce orders without paying.
| Vendor | unknown |
| Product | flxwoo |
| Published | Jul 31, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown flxwoo
Be the first to know when new unknown vulnerabilities affecting unknown flxwoo are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / FlxWoo
0 < 3.1.1
References
Credits
Pedro Pinho WPScan