Description
The Razorpay for WooCommerce WordPress plugin before 4.8.8 does not perform ownership or authorization checks on a REST API route used during checkout, allowing unauthenticated attackers to modify the shipping information stored on arbitrary orders.
Published: 2026-10-04
Score: n/a
EPSS: n/a
KEV: No
Impact: Unauthorized modification of order shipping information
Action: Immediate Patch
AI Analysis

Impact

The Razorpay for WooCommerce plugin versions prior to 4.8.8 lack proper ownership or authorization checks on a REST API route that is invoked during checkout. As a result, unauthenticated attackers can modify the shipping details stored on any order. The attacker can change addresses to redirect deliveries, potentially leading to fraud or loss of goods, and compromising customer privacy. This reflects an Insecure Direct Object Reference flaw (CWE-284).

Affected Systems

Any WordPress site using the Razorpay for WooCommerce plugin with a version older than 4.8.8 is affected. The vulnerability is tied to the REST API endpoint used during the checkout process and is present in all installations of the plugin that have not been updated to the patched release.

Risk and Exploitability

Because the flaw permits unauthenticated modification, the attack vector is a simple HTTP request to the vulnerable REST endpoint. The attack requires knowledge of the order identifier, but no additional authentication or privilege escalation is needed. While no exploitation reports or EPSS data are available, the impact of altering shipping information is high, and the vulnerability is suitable for low‑skill attackers. The absence of a known public exploit does not reduce the risk, as the conditions for exploitation are trivial and the consequences are significant.

Generated by OpenCVE AI on October 4, 2026 at 07:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Razorpay for WooCommerce to version 4.8.8 or later, which enforces proper ownership checks on the order shipping REST endpoint.
  • If an immediate upgrade is not possible, temporarily disable the vulnerable REST API route or restrict its use to authenticated users only, ensuring that only legitimate application or administrative actions can modify order shipping data.
  • Apply general access‑control best practices: verify ownership of order resources before processing any state‑changing requests, and audit the plugin for similar authorization gaps.

Generated by OpenCVE AI on October 4, 2026 at 07:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 04 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sun, 04 Oct 2026 06:45:00 +0000

Type Values Removed Values Added
Description The Razorpay for WooCommerce WordPress plugin before 4.8.8 does not perform ownership or authorization checks on a REST API route used during checkout, allowing unauthenticated attackers to modify the shipping information stored on arbitrary orders.
Title Razorpay for WooCommerce < 4.8.8 - Unauthenticated Order Shipping Modification via IDOR
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-04T06:00:23.107Z

Reserved: 2026-10-01T18:12:49.242Z

Link: CVE-2026-104118

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-04T07:16:31.933

Modified: 2026-10-04T07:16:31.933

Link: CVE-2026-104118

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-04T07:30:09Z

Weaknesses