CVE-2026-13692
Received Received - Intake

Unauthenticated Payment Tampering in PayU CommercePro WordPress Plugin

Vulnerability report for CVE-2026-13692, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-29

Last updated on: 2026-07-29

Assigner: WPScan

Description

The PayU CommercePro Plugin WordPress plugin through 3.8.9 does not verify the payment-gateway signature before applying order modifications, allowing unauthenticated attackers to tamper with the totals, shipping and metadata of arbitrary WooCommerce orders.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-29
Last Modified
2026-07-29
Generated
2026-07-29
AI Q&A
2026-07-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
payu commercepro_plugin to 3.8.9 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The PayU CommercePro Plugin for WordPress has a flaw where it does not check payment-gateway signatures before modifying orders. This lets unauthenticated attackers change order totals, shipping, or metadata by sending fake webhook requests. The changes persist even if later checks fail.

Detection Guidance

Check if the PayU CommercePro plugin version is 3.8.9 or earlier. Use commands like 'wp plugin list' in WordPress CLI or inspect the plugin directory for version details. Monitor webhook requests to WooCommerce for suspicious modifications to order totals, shipping, or metadata.

Impact Analysis

Attackers could reduce order totals to zero or alter shipping and metadata without authentication. This could lead to financial losses, incorrect order processing, or fraudulent transactions. The attack is simple and requires no special access.

Compliance Impact

This vulnerability could lead to unauthorized modifications of order data, potentially exposing sensitive customer information such as payment details, shipping addresses, or order metadata. Such unauthorized changes may violate GDPR if personal data is altered without consent or proper authorization. For HIPAA, if the plugin handles protected health information in order processing, tampering could compromise data integrity and confidentiality requirements.

Mitigation Strategies

Update the PayU CommercePro plugin to the latest version immediately. Disable webhook processing temporarily if possible. Review recent orders for unauthorized changes and revert any tampered data. Implement additional signature verification for webhook requests.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-13692. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart