CVE-2026-16962
Tamara Checkout <= 1.9.9.20 - Unauthenticated Order Status Manipulation
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Tamara Checkout WordPress plugin through 1.9.9.20 does not verify the order key, a nonce, or any capability on its public payment cancel/fail return URLs, changing a WooCommerce order's status based solely on an attacker-supplied numeric order id, so an unauthenticated attacker can cancel or fail arbitrary orders store-wide by enumerating ids (triggering downstream stock-release and notification side-effects).
| Vendor | unknown |
| Product | tamara checkout |
| Published | Aug 21, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown tamara checkout
Be the first to know when new unknown vulnerabilities affecting unknown tamara checkout are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Tamara Checkout
0 โค 1.9.9.20
References
Credits
Ezekiel Victor WPScan