๐Ÿ” CVE Alert

CVE-2026-81649

UNKNOWN 0.0

Fundiin <= 3.4.0 - Unauthenticated Payment Gateway Settings Update and Credential Disclosure

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Fundiin cho WooCommerce WordPress plugin through 3.4.0 does not have proper authorisation on several of its REST API routes, relying instead on a credential that is identical on every installation, allowing unauthenticated attackers to disclose the store's payment credentials and customer order data, overwrite the payment gateway configuration so that payments are credited elsewhere, and mark unpaid orders as paid. The same missing authorisation also allows arbitrary script to be stored in a field which is output unescaped on the classic checkout, leading to unauthenticated stored XSS on stores that do not use the block-based checkout.

Vendor unknown
Product fundiin cho woocommerce
Published Oct 11, 2026
Stay Ahead of the Next One

Get instant alerts for unknown fundiin cho woocommerce

Be the first to know when new unknown vulnerabilities affecting unknown fundiin cho woocommerce are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Fundiin cho WooCommerce
0 โ‰ค 3.4.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/28cec871-1f17-48c7-b836-db705fc5cffa/

Credits

WPScan