CVE-2026-81649
Received Received - Intake

Authentication Bypass and Stored XSS in Fundiin cho WooCommerce Plugin

Vulnerability report for CVE-2026-81649, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: WPScan

Description

The Fundiin cho WooCommerce WordPress plugin through 3.4.0 does not have proper authorisation on several of its REST API routes, relying instead on a credential that is identical on every installation, allowing unauthenticated attackers to disclose the store's payment credentials and customer order data, overwrite the payment gateway configuration so that payments are credited elsewhere, and mark unpaid orders as paid. The same missing authorisation also allows arbitrary script to be stored in a field which is output unescaped on the classic checkout, leading to unauthenticated stored XSS on stores that do not use the block-based checkout.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown Fundiin cho WooCommerce 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Fundiin WooCommerce WordPress plugin versions 3.4.0 and below. It is caused by improper authorization checks on REST API routes, allowing unauthenticated attackers to exploit a hardcoded credential shared across all installations. This enables them to access sensitive payment and customer data, modify payment settings, falsify order statuses, and inject malicious scripts leading to stored XSS attacks.

Detection Guidance

Check if the Fundiin WooCommerce plugin version 3.4.0 or below is installed. Look for unauthorized API calls or unusual payment gateway modifications. Monitor for stored XSS attempts in checkout fields. Use WPScan to detect vulnerable versions.

Impact Analysis

If you use the affected Fundiin plugin, attackers could steal your store's payment credentials and customer order data. They could also redirect payments to their accounts, mark unpaid orders as paid, and inject malicious scripts into your checkout page, potentially compromising your customers' data and your website's security.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA due to unauthorized access to sensitive customer data, including payment information and order details. It may result in data breaches, violating privacy regulations and potentially leading to legal penalties and reputational damage.

Mitigation Strategies

Update the Fundiin WooCommerce plugin to the latest version immediately. Disable the plugin if no update is available. Review payment gateway settings for unauthorized changes. Implement strict access controls on REST API routes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81649. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart