WooCommerce 的 Razorpay 插件在 4.8.8 版本之前,在结账过程中使用的 REST API 路由上未执行所有权或授权检查,导致未认证的攻击者可以修改任意订单中存储的 shipping 信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Razorpay for WooCommerce | 0 ~ 4.8.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93549 | CoCart 4.9.0 - 4.9.6 - Administrator Account Creation via REST API Authentication Bypass | |
| CVE-2026-97332 | User Private Files < 2.2.0 - Unauthenticated Private File Disclosure via .htaccess Rewrite | |
| CVE-2026-86817 | Five Star Business Profile and Schema 2.3.20 - 2.3.21 - Author+ Sensitive Data Disclosure | |
| CVE-2026-17005 | Horizontal Scrolling Announcements <= 2.6 - Contributor+ Stored XSS via Style Field | |
| CVE-2026-104119 | Simple Shopping Cart < 5.2.6 - Admin+ Stored XSS via PayPal API Credentials |
No comments yet