CVE-2026-12966
Received Received - Intake

Unauthenticated Order Status Tampering in Direct Payments for WooCommerce

Vulnerability report for CVE-2026-12966, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-01

Last updated on: 2026-08-01

Assigner: WPScan

Description

The Direct Payments for WooCommerce WordPress plugin before 2.5.3 does not verify that the requester owns the targeted WooCommerce order in several unauthenticated AJAX handlers before changing its status and overwriting its payment metadata, allowing unauthenticated attackers to tamper with other customers' orders, including forging a "payment sent" state, overwriting the payment-method label, and attaching forged payment-proof files.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-01
Last Modified
2026-08-01
Generated
2026-08-01
AI Q&A
2026-08-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
woocommerce direct_payments to 2.5.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the Direct Payments for WooCommerce plugin for WordPress. It allows unauthenticated attackers to manipulate WooCommerce orders without verifying ownership. Attackers can change order statuses, forge payment states, overwrite payment methods, and attach fake payment proofs.

Detection Guidance

To detect this vulnerability, check if your WordPress site uses the Direct Payments for WooCommerce plugin version before 2.5.3. Inspect the plugin files for unauthenticated AJAX handlers that modify order status or payment metadata without ownership verification. Look for suspicious changes in order statuses or payment proofs.

Impact Analysis

Unauthenticated attackers could tamper with your orders, mark orders as paid without actual payment, change payment methods, or attach forged payment proofs. This could lead to financial loss, incorrect order processing, or fraudulent transactions.

Compliance Impact

This vulnerability allows unauthenticated attackers to tamper with customer orders, including forging payment states and altering payment metadata. This could lead to unauthorized access or modification of sensitive customer data, potentially violating GDPR (data protection) and HIPAA (healthcare data privacy) compliance by exposing or altering protected information without consent.

Mitigation Strategies

Update the Direct Payments for WooCommerce plugin to version 2.5.3 or later to address the vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12966. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart