Retour aux alertes CVE
CVE-2026-9028 MEDIUM CVSS 5.3

CVE-2026-9028 — MEDIUM

Publiée 1 month ago Fiche NVD officielle

Qu'est-ce que c'est ?

The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.7.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to cancel any WooCommerce order placed via the CorvusPay payment method by supplying an arbitrary order number to the /wp-json/corvuspay/cancel/ REST endpoint.

Technologies affectées

Non précisé par la fiche NVD.

Recommandation

Vérifie la disponibilité d'un correctif pour la technologie concernée et applique-le dès que possible. Consulte la fiche NVD pour les références officielles du fournisseur.

Exploits publics connus (0)

Aucun proof-of-concept public trouvé sur GitHub à ce jour. Ça peut changer : les PoC sont souvent publiés plusieurs jours ou semaines après la divulgation.