CVE-2026-14830
Received Received - Intake

Unauthenticated Order Completion in FlxWoo WordPress Plugin

Vulnerability report for CVE-2026-14830, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-31

Last updated on: 2026-07-31

Assigner: WPScan

Description

The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout session was actually paid before marking the associated order as paid, allowing unauthenticated attackers to complete WooCommerce orders without paying.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-31
Last Modified
2026-07-31
Generated
2026-07-31
AI Q&A
2026-07-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
flxwoo flxwoo to 3.1.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The FlxWoo WordPress plugin before version 3.1.1 has a flaw where it does not check with the payment processor to confirm if a checkout session was paid before marking an order as paid. This allows unauthenticated attackers to complete WooCommerce orders without making any payment.

Detection Guidance

Check the installed version of the FlxWoo WordPress plugin. If it is below 3.1.1, the system is vulnerable. Use commands like 'wp plugin list' in WordPress CLI or inspect the plugin files directly.

Impact Analysis

This vulnerability could lead to financial losses as orders are marked as paid without actual payment. It may also damage customer trust and business reputation. Unauthorized orders could disrupt inventory and order management systems.

Compliance Impact

This vulnerability could lead to unauthorized transactions, potentially violating data protection and financial compliance requirements under standards like GDPR and HIPAA. Unpaid orders may result in improper handling of personal or financial data, exposing organizations to legal and regulatory penalties.

Mitigation Strategies

Update the FlxWoo plugin to version 3.1.1 or later immediately. Disable the plugin temporarily if an update is not immediately available. Review recent WooCommerce orders for unauthorized completions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14830. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart