WordPress PhonePe Payment Solutions是WordPress基金会的一款支付解决方案软件。 WordPress PhonePe Payment Solutions 3.1.0之前版本存在授权问题漏洞,该漏洞源于未能正确验证传入支付回调的真实性,用于验证回调签名的密钥为空,导致预期签名简化为任何人可计算的请求体无密钥哈希,允许未经身份验证的攻击者伪造支付成功通知并将未支付的WooCommerce订单标记为已支付。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | PhonePe Payment Solutions | < 3.1.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | PhonePe Payment Solutions | 0 ~ 3.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-9810 | AI Chatbot & Workflow Automation by AIWU < 1.5.4 - Unauthenticated Privilege Escalation vi | |
| CVE-2026-13402 | Royal Elementor Addons < 1.7.1063 - Unauthenticated Private Mega Menu Template Disclosure | |
| CVE-2026-11961 | User Registration & Membership < 5.2.3 - Unauthenticated Privilege Escalation via Unbound | |
| CVE-2026-11966 | User Registration & Membership < 5.2.3 - Unauthenticated Limited User Deletion via Stripe | |
| CVE-2026-10525 | NEX-Forms < 9.2.3 - Unauthenticated Stored XSS via Form Submission | |
| CVE-2026-12393 | WPS Bookings for WooCommerce < 3.11.7 - Subscriber+ Arbitrary Booking Order Cancellation v |
No comments yet