๐Ÿ” CVE Alert

CVE-2026-7862

HIGH 8.6

Eupago Gateway For Woocommerce < 4.7.2 - Unauthenticated Arbitrary Refund Initiation

CVSS Score
8.6
EPSS Score
0.0%
EPSS Percentile
0th

The Eupago Gateway For Woocommerce WordPress plugin before 4.7.2 does not properly restrict access to its refund request handler, allowing unauthenticated attackers to initiate refunds against any WooCommerce order using the merchant's payment gateway credentials, and for applicable payment methods, to redirect refunded funds to an attacker-controlled bank account.

Vendor unknown
Product eupago gateway for woocommerce
Published May 28, 2026
Last Updated May 28, 2026
Stay Ahead of the Next One

Get instant alerts for unknown eupago gateway for woocommerce

Be the first to know when new high vulnerabilities affecting unknown eupago gateway for woocommerce are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Eupago Gateway For Woocommerce
0 < 4.7.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/b4ce2a06-b435-4b77-851f-4406f2a91ca6/

Credits

Pedro Pinho WPScan