UPI QR Code Payment Gateway WordPress 插件版本 1.4.3 及之前版本存在一个安全漏洞。该漏洞源于插件未验证支付确认请求是否确实属于它所声称确认的订单和客户,从而导致未认证的攻击者可以在不进行任何支付的情况下,将任意订单标记为已支付。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | UPI QR Code Payment Gateway | 0 ~ 1.4.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-13607 | File Uploads Addon for WooCommerce <= 1.7.6 - Unauthenticated Direct File Access | |
| CVE-2026-78371 | File Uploads Addon for WooCommerce 1.7.2 - 1.7.5 - Unauthenticated Customer Uploaded File |
No comments yet