Description
The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.4 does not verify that a payment-confirmation request originates from the owner of the targeted order, nor that any payment actually occurred, allowing unauthenticated attackers to mark arbitrary orders as confirmed and, in a non-default configuration, paid.
Published: 2026-08-14
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw exists in the Epeken All Kurir for WooCommerce plugin up to version 2.1.4 where the code accepts a payment‑confirmation request without verifying the request originates from the legitimate order owner or that any payment has actually occurred. This omission reflects a CWE‑287 Authentication Failure and enables unauthenticated attackers to mark any order as confirmed, and in a non‑default configuration to also set it to paid. The result is a severe compromise of order integrity and a potential for billing fraud.

Affected Systems

The Epeken All Kurir integration is used on WordPress e‑commerce sites to collect courier information for WooCommerce. Any installation of the plugin version 2.1.4 or earlier is affected. Administrators and site owners should verify the plugin version and apply available updates.

Risk and Exploitability

Based on the description, the likely attack vector is an unauthenticated POST request to the plugin's payment‑confirmation endpoint. Because the plugin performs no authentication or ownership checks, the attack can succeed from any external source. The EPSS score is reported as less than 1%, indicating a very low exploitation probability. The CVSS score of 5.9 denotes a medium severity due to ease of use and potential financial impact. The vulnerability is not listed in the CISA KEV catalog, but its presence still warrants prompt action.

Generated by OpenCVE AI on August 31, 2026 at 11:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Epeken All Kurir plugin to a version newer than 2.1.4, where the order‑confirmation validation has been implemented.
  • If an immediate update is not possible, disable the external payment‑confirmation functionality or configure the plugin to prevent orders from being marked as paid automatically.
  • Restrict access to the payment‑confirmation endpoint by applying role‑based access controls or IP whitelisting so that only trusted administrators can trigger confirmation actions.

Generated by OpenCVE AI on August 31, 2026 at 11:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Description The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.2 does not verify that a payment-confirmation request originates from the owner of the targeted order, nor that any payment actually occurred, allowing unauthenticated attackers to mark arbitrary orders as confirmed and, in a non-default configuration, paid. The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.4 does not verify that a payment-confirmation request originates from the owner of the targeted order, nor that any payment actually occurred, allowing unauthenticated attackers to mark arbitrary orders as confirmed and, in a non-default configuration, paid.
Title Epeken All Kurir <= 2.1.2 - Unauthenticated Order Payment Confirmation Forgery Epeken All Kurir <= 2.1.4 - Unauthenticated Order Payment Confirmation Forgery

Fri, 14 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 14 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 14 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 14 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.2 does not verify that a payment-confirmation request originates from the owner of the targeted order, nor that any payment actually occurred, allowing unauthenticated attackers to mark arbitrary orders as confirmed and, in a non-default configuration, paid.
Title Epeken All Kurir <= 2.1.2 - Unauthenticated Order Payment Confirmation Forgery
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-31T09:08:34.173Z

Reserved: 2026-07-23T08:17:21.130Z

Link: CVE-2026-16739

cve-icon Vulnrichment

Updated: 2026-08-14T15:36:16.691Z

cve-icon NVD

Status : Deferred

Published: 2026-08-14T06:17:03.153

Modified: 2026-08-31T09:17:02.457

Link: CVE-2026-16739

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T11:45:17Z

Weaknesses