PatchSiren cyber security CVE debrief
CVE-2026-16739 Epeken CVE debrief
The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.2 does not verify that a payment-confirmation request originates from the owner of the targeted order, nor that any payment actually occurred, allowing unauthenticated attackers to mark arbitrary orders as confirmed and, in a non-default configuration, paid. This vulnerability, with a CVSS score of 5.9 and a severity of MEDIUM, enables attackers to modify order statuses without proper authentication, potentially leading to unauthorized changes in order confirmations and payments. Administrators and users of the Epeken All Kurir for Woocommerce WordPress plugin, especially those with WooCommerce-based online stores, should be aware of this vulnerability and take necessary defensive actions to prevent unauthorized order modifications. The vulnerability allows unauthenticated attackers to mark arbitrary orders as confirmed and, in a non-default configuration, paid, due to a lack of verification for payment-confirmation requests. Defenders should verify affected product deployments, review official advisories, and plan vendor-supported updates or mitigations.
- Vendor
- Epeken
- Product
- All Kurir for Woocommerce
- CVSS
- MEDIUM 5.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-14
- Original CVE updated
- 2026-08-26
- Advisory published
- 2026-08-14
- Advisory updated
- 2026-08-26
Who should care
Administrators and users of the Epeken All Kurir for Woocommerce WordPress plugin, especially those with WooCommerce-based online stores, should be aware of this vulnerability and take necessary defensive actions to prevent unauthorized order modifications.
Technical summary
The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.2 is vulnerable to unauthorized order status modifications. Unauthenticated attackers can mark arbitrary orders as confirmed and, in certain configurations, paid. This is due to a lack of verification for payment-confirmation requests, specifically checking if the request originates from the order owner and if a payment actually occurred. The vulnerability has a CVSS score of 5.9 and a severity of MEDIUM.
Defensive priority
Medium-priority defensive review recommended due to potential for unauthorized order modifications.
Recommended defensive actions
- Review and update the Epeken All Kurir for Woocommerce WordPress plugin to version above 2.1.2
- Implement additional authentication and validation for payment-confirmation requests
- Monitor order status changes for potential unauthorized modifications
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
Evidence from WPScan indicates a vulnerability in the Epeken All Kurir for Woocommerce WordPress plugin. Official CVE and NVD records provide additional context. The vulnerability allows unauthenticated attackers to mark arbitrary orders as confirmed and, in a non-default configuration, paid. Defenders should verify affected product deployments, review official advisories, and plan vendor-supported updates or mitigations.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-16739 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-16739
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-16739 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-16739
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/b66b86f9-e49e-4654-84a1-0f2e5c859289/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.