PatchSiren cyber security CVE debrief
CVE-2026-12972 PayPlus CVE debrief
The PayPlus Payment Gateway WordPress plugin before 8.2.2 is vulnerable to unauthorized tampering of payment-related metadata of arbitrary WooCommerce orders due to a lack of authorization and order-ownership validation in one of its AJAX actions. This action is accessible to unauthenticated users, potentially allowing them to modify order information without proper checks. Users of the plugin should verify that they are running version 8.2.2 or later to address this vulnerability. The issue was reported by Wpscan, highlighting the importance of robust validation and authorization mechanisms in e-commerce plugins.
- Vendor
- PayPlus
- Product
- Payment Gateway WordPress plugin
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-20
- Original CVE updated
- 2026-07-20
- Advisory published
- 2026-07-20
- Advisory updated
- 2026-07-20
Who should care
Users of the PayPlus Payment Gateway WordPress plugin, particularly those managing e-commerce sites with WooCommerce, should verify that they are running version 8.2.2 or later to address this vulnerability. Site administrators, security teams, and e-commerce platform managers are advised to review their installations and update as necessary to prevent unauthorized tampering with payment metadata. Additionally, security professionals and WooCommerce site owners should be aware of the potential risks associated with this vulnerability and take appropriate measures to protect their sites.
Technical summary
The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform necessary authorization or order-ownership validation in one of its AJAX actions. This omission allows unauthenticated users to tamper with the payment-related metadata of arbitrary WooCommerce orders. The vulnerability stems from the plugin's failure to properly secure its AJAX actions, making it crucial for users to update to version 8.2.2 or later to mitigate this risk. The technical details of the vulnerability involve the exploitation of an insecure AJAX action to modify order metadata without proper validation.
Defensive priority
High
Recommended defensive actions
- Verify and apply the vendor's patch to update the PayPlus Payment Gateway WordPress plugin to version 8.2.2 or later.
- Review and restrict access to AJAX actions to ensure proper authorization and validation.
- Monitor for suspicious activity related to WooCommerce orders and payment metadata.
- Perform a thorough review of the plugin's configuration and security settings.
- Consider implementing additional security measures, such as enhanced logging and monitoring, to detect potential exploitation attempts.
- Conduct regular security audits and vulnerability assessments for all e-commerce plugins and components.
- Ensure that all site administrators and relevant personnel are informed about the vulnerability and the necessary remediation steps.
Evidence notes
Evidence is limited; verification of vulnerability details is recommended through official channels and vendor statements. The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to tamper with the payment-related metadata of arbitrary WooCommerce orders. This issue was reported by Wpscan, which identified the vulnerability and provided details about its nature.
Official resources
-
CVE-2026-12972 CVE record
CVE.org
-
CVE-2026-12972 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-20T07:16:35.290Z and has not been modified since then.