CVE-2026-84169
Received Received - Intake

UPI QR Code Payment Gateway Unauthenticated Payment Confirmation

Vulnerability report for CVE-2026-84169, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: WPScan

Description

The UPI QR Code Payment Gateway WordPress plugin through 1.4.3 does not verify that a payment-confirmation request actually belongs to the order and customer it claims to confirm, allowing unauthenticated attackers to mark an arbitrary order as paid without making any payment.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
upi_qr_code_payment_gateway plugin 1.4.3
wpupiqr upi_qr_code_payment_gateway to 1.4.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an unauthenticated cross-order payment-status forgery in the UPI QR Code Payment Gateway WordPress plugin up to version 1.4.3. The plugin fails to verify that a payment-confirmation request matches the correct order and customer, allowing attackers to mark any order as paid without making an actual payment.

Detection Guidance

To detect this vulnerability, check if your WordPress site uses the UPI QR Code Payment Gateway plugin version 1.4.3 or lower. Inspect network traffic for unauthenticated payment-confirmation requests that modify order status without valid payments. Look for suspicious POST requests to payment confirmation endpoints.

Impact Analysis

Attackers could exploit this to trick the system into marking orders as paid without receiving payment, leading to financial losses for merchants. Customers might receive products or services without valid payment, causing disputes and chargebacks.

Compliance Impact

This vulnerability could lead to unauthorized transactions being marked as paid, potentially violating data integrity and financial compliance requirements in standards like GDPR (for payment data handling) and HIPAA (if payment data relates to healthcare transactions). Unauthorized order confirmations may also breach audit trails required by these regulations.

Mitigation Strategies

Immediately update the UPI QR Code Payment Gateway WordPress plugin to the latest version beyond 1.4.3 to patch the vulnerability. If an update is not available, consider disabling or removing the plugin until a fix is released.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84169. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart