PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-16739 Epeken CVE debrief

The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.2 does not verify that a payment-confirmation request originates from the owner of the targeted order, nor that any payment actually occurred, allowing unauthenticated attackers to mark arbitrary orders as confirmed and, in a non-default configuration, paid. This vulnerability, with a CVSS score of 5.9 and a severity of MEDIUM, enables attackers to modify order statuses without proper authentication, potentially leading to unauthorized changes in order confirmations and payments. Administrators and users of the Epeken All Kurir for Woocommerce WordPress plugin, especially those with WooCommerce-based online stores, should be aware of this vulnerability and take necessary defensive actions to prevent unauthorized order modifications. The vulnerability allows unauthenticated attackers to mark arbitrary orders as confirmed and, in a non-default configuration, paid, due to a lack of verification for payment-confirmation requests. Defenders should verify affected product deployments, review official advisories, and plan vendor-supported updates or mitigations.

Vendor
Epeken
Product
All Kurir for Woocommerce
CVSS
MEDIUM 5.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-14
Original CVE updated
2026-08-26
Advisory published
2026-08-14
Advisory updated
2026-08-26

Who should care

Administrators and users of the Epeken All Kurir for Woocommerce WordPress plugin, especially those with WooCommerce-based online stores, should be aware of this vulnerability and take necessary defensive actions to prevent unauthorized order modifications.

Technical summary

The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.2 is vulnerable to unauthorized order status modifications. Unauthenticated attackers can mark arbitrary orders as confirmed and, in certain configurations, paid. This is due to a lack of verification for payment-confirmation requests, specifically checking if the request originates from the order owner and if a payment actually occurred. The vulnerability has a CVSS score of 5.9 and a severity of MEDIUM.

Defensive priority

Medium-priority defensive review recommended due to potential for unauthorized order modifications.

Recommended defensive actions

  • Review and update the Epeken All Kurir for Woocommerce WordPress plugin to version above 2.1.2
  • Implement additional authentication and validation for payment-confirmation requests
  • Monitor order status changes for potential unauthorized modifications
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

Evidence from WPScan indicates a vulnerability in the Epeken All Kurir for Woocommerce WordPress plugin. Official CVE and NVD records provide additional context. The vulnerability allows unauthenticated attackers to mark arbitrary orders as confirmed and, in a non-default configuration, paid. Defenders should verify affected product deployments, review official advisories, and plan vendor-supported updates or mitigations.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-16739 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-16739

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-16739 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-16739

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.