PatchSiren

PayPlus CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review PayPlus CVE published 2026-07-20

CVE-2026-12973

The PayPlus Payment Gateway WordPress plugin before 8.2.2 has a vulnerability that allows unauthenticated users to disclose the secret order key of arbitrary WooCommerce orders and potentially modify order statuses due to a lack of authorization and order-ownership validation in one of its AJAX actions. This vulnerability has a high impact on users of the PayPlus Payment Gateway WordPress plugin, especial [truncated]

Review PayPlus CVE published 2026-07-20

CVE-2026-12972

The PayPlus Payment Gateway WordPress plugin before 8.2.2 is vulnerable to unauthorized tampering of payment-related metadata of arbitrary WooCommerce orders due to a lack of authorization and order-ownership validation in one of its AJAX actions. This action is accessible to unauthenticated users, potentially allowing them to modify order information without proper checks. Users of the plugin should veri [truncated]