CVE-2026-7862
Eupago Gateway For Woocommerce < 4.7.2 - Unauthenticated Arbitrary Refund Initiation
CVSS Score
8.6
EPSS Score
0.0%
EPSS Percentile
0th
The Eupago Gateway For Woocommerce WordPress plugin before 4.7.2 does not properly restrict access to its refund request handler, allowing unauthenticated attackers to initiate refunds against any WooCommerce order using the merchant's payment gateway credentials, and for applicable payment methods, to redirect refunded funds to an attacker-controlled bank account.
| Vendor | unknown |
| Product | eupago gateway for woocommerce |
| Published | May 28, 2026 |
| Last Updated | May 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown eupago gateway for woocommerce
Be the first to know when new high vulnerabilities affecting unknown eupago gateway for woocommerce are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Eupago Gateway For Woocommerce
0 < 4.7.2
References
Credits
Pedro Pinho WPScan