PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-12972 PayPlus CVE debrief

The PayPlus Payment Gateway WordPress plugin before 8.2.2 is vulnerable to unauthorized tampering of payment-related metadata of arbitrary WooCommerce orders due to a lack of authorization and order-ownership validation in one of its AJAX actions. This action is accessible to unauthenticated users, potentially allowing them to modify order information without proper checks. Users of the plugin should verify that they are running version 8.2.2 or later to address this vulnerability. The issue was reported by Wpscan, highlighting the importance of robust validation and authorization mechanisms in e-commerce plugins.

Vendor
PayPlus
Product
Payment Gateway WordPress plugin
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-20
Original CVE updated
2026-07-21
Advisory published
2026-07-20
Advisory updated
2026-07-21

Who should care

Users of the PayPlus Payment Gateway WordPress plugin, particularly those managing e-commerce sites with WooCommerce, should verify that they are running version 8.2.2 or later to address this vulnerability. Site administrators, security teams, and e-commerce platform managers are advised to review their installations and update as necessary to prevent unauthorized tampering with payment metadata. Additionally, security professionals and WooCommerce site owners should be aware of the potential risks associated with this vulnerability and take appropriate measures to protect their sites.

Technical summary

The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform necessary authorization or order-ownership validation in one of its AJAX actions. This omission allows unauthenticated users to tamper with the payment-related metadata of arbitrary WooCommerce orders. The vulnerability stems from the plugin's failure to properly secure its AJAX actions, making it crucial for users to update to version 8.2.2 or later to mitigate this risk. The technical details of the vulnerability involve the exploitation of an insecure AJAX action to modify order metadata without proper validation.

Defensive priority

High

Recommended defensive actions

  • Verify and apply the vendor's patch to update the PayPlus Payment Gateway WordPress plugin to version 8.2.2 or later.
  • Review and restrict access to AJAX actions to ensure proper authorization and validation.
  • Monitor for suspicious activity related to WooCommerce orders and payment metadata.
  • Perform a thorough review of the plugin's configuration and security settings.
  • Consider implementing additional security measures, such as enhanced logging and monitoring, to detect potential exploitation attempts.
  • Conduct regular security audits and vulnerability assessments for all e-commerce plugins and components.
  • Ensure that all site administrators and relevant personnel are informed about the vulnerability and the necessary remediation steps.

Evidence notes

Evidence is limited; verification of vulnerability details is recommended through official channels and vendor statements. The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to tamper with the payment-related metadata of arbitrary WooCommerce orders. This issue was reported by Wpscan, which identified the vulnerability and provided details about its nature.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-12972 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-12972

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-12972 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-12972

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.