Review
Fundiin
CVE published 2026-10-11
CVE-2026-81649
The Fundiin cho WooCommerce WordPress plugin through 3.4.0 has missing authorization on several REST API routes, allowing unauthenticated attackers to disclose payment credentials and customer order data, overwrite payment gateway configurations, and mark unpaid orders as paid. The plugin also allows arbitrary scripts to be stored in a field output unescaped on the classic checkout, leading to unauthentic [truncated]