PatchSiren

Fundiin CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review Fundiin CVE published 2026-10-11

CVE-2026-81649

The Fundiin cho WooCommerce WordPress plugin through 3.4.0 has missing authorization on several REST API routes, allowing unauthenticated attackers to disclose payment credentials and customer order data, overwrite payment gateway configurations, and mark unpaid orders as paid. The plugin also allows arbitrary scripts to be stored in a field output unescaped on the classic checkout, leading to unauthentic [truncated]