HIGH
FlxWoo
CVE published 2026-07-31
CVE-2026-14830
The FlxWoo WordPress plugin before 3.1.1 is vulnerable to unauthorized order completion. The plugin fails to verify with the payment processor that a checkout session was actually paid before marking the associated order as paid. This allows unauthenticated attackers to complete WooCommerce orders without making a payment, potentially leading to financial losses for affected sites. The vulnerability is pa [truncated]