Impact
The Razorpay for WooCommerce plugin versions prior to 4.8.8 lack proper ownership or authorization checks on a REST API route that is invoked during checkout. As a result, unauthenticated attackers can modify the shipping details stored on any order. The attacker can change addresses to redirect deliveries, potentially leading to fraud or loss of goods, and compromising customer privacy. This reflects an Insecure Direct Object Reference flaw (CWE-284).
Affected Systems
Any WordPress site using the Razorpay for WooCommerce plugin with a version older than 4.8.8 is affected. The vulnerability is tied to the REST API endpoint used during the checkout process and is present in all installations of the plugin that have not been updated to the patched release.
Risk and Exploitability
Because the flaw permits unauthenticated modification, the attack vector is a simple HTTP request to the vulnerable REST endpoint. The attack requires knowledge of the order identifier, but no additional authentication or privilege escalation is needed. While no exploitation reports or EPSS data are available, the impact of altering shipping information is high, and the vulnerability is suitable for low‑skill attackers. The absence of a known public exploit does not reduce the risk, as the conditions for exploitation are trivial and the consequences are significant.
OpenCVE Enrichment