Description
Missing Authorization vulnerability in knitpay Razorpay Payment Links for WooCommerce rzp-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Razorpay Payment Links for WooCommerce: from n/a through <= 2.1.4.
Published: 2026-07-13
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Razorpay Payment Links for WooCommerce plugin contains a missing authorization check that permits users without proper privileges to access or alter payment link configurations. This flaw is classified as improper authorization (CWE-862) and could lead to unauthorized changes to transaction settings or exposure of sensitive financial data.

Affected Systems

WordPress installations that use the knitpay Razorpay Payment Links for WooCommerce plugin version 2.1.4 or earlier are affected. Any site running a vulnerable version and not updated beyond 2.1.4 is susceptible, regardless of other WordPress configuration.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity impact on confidentiality, integrity, and availability. The EPSS score, being less than 1%, suggests a very low likelihood of exploitation under current conditions, and the vulnerability is not listed in the CISA KEV catalog. Attackers would likely need access to a user account with elevated privileges or exploit a misconfigured role to leverage this broken access control. In the absence of such conditions, the risk remains largely theoretical, yet the potential damage warrants prompt attention.

Generated by OpenCVE AI on July 29, 2026 at 07:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Razorpay Payment Links for WooCommerce plugin to the latest available version to eliminate the missing authorization flaw.
  • Limit administrative privileges to trusted users; configure WordPress roles so that only required users can modify payment link settings.
  • Review and audit user accounts for excessive privileges or misassigned roles that could enable exploitation.

Generated by OpenCVE AI on July 29, 2026 at 07:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Knitpay
Knitpay razorpay Payment Links For Woocommerce
Wordpress
Wordpress wordpress
Vendors & Products Knitpay
Knitpay razorpay Payment Links For Woocommerce
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in knitpay Razorpay Payment Links for WooCommerce rzp-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Razorpay Payment Links for WooCommerce: from n/a through <= 2.1.4.
Title WordPress Razorpay Payment Links for WooCommerce plugin <= 2.1.4 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Knitpay Razorpay Payment Links For Woocommerce
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T13:32:13.317Z

Reserved: 2026-06-24T12:46:44.604Z

Link: CVE-2026-57424

cve-icon Vulnrichment

Updated: 2026-07-13T13:31:49.185Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T08:00:04Z

Weaknesses