CVE-2026-84169
Received
Received - Intake
UPI QR Code Payment Gateway Unauthenticated Payment Confirmation
Vulnerability report for CVE-2026-84169, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-05
Last updated on: 2026-10-05
Assigner: WPScan
Description
Description
The UPI QR Code Payment Gateway WordPress plugin through 1.4.3 does not verify that a payment-confirmation request actually belongs to the order and customer it claims to confirm, allowing unauthenticated attackers to mark an arbitrary order as paid without making any payment.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| upi_qr_code_payment_gateway | plugin | 1.4.3 |
| wpupiqr | upi_qr_code_payment_gateway | to 1.4.3 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |