PatchSiren

Razorpay CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Razorpay CVE published 2026-04-08

CVE-2026-39656

A Missing Authorization vulnerability in Razorpay Razorpay for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Razorpay for WooCommerce: from n/a through <= 4.8.2. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. Users of Razorpay for WooCommerce, especially those with versions from n/a through <= 4.8.2, should be aware [truncated]