CVE-2026-12972
The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX ac
CVSS
5.3
Medium
EPSS
0.3%
p22
KEV
—
Exploit Today
7
0-100
Published: Jul 20, 2026 · Last modified: Jul 21, 2026 · CWE-284
0.2%EPSS · 30 days0.3%
2026-08-102026-09-07
The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to tamper with the payment-related metadata of arbitrary WooCommerce orders.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-692828.8 HIG—
———Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.57mCVE-2026-692738.8 HIG—
———Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.36mCVE-2026-692688.8 HIG—
———Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.36mCVE-2026-843855.4 MED—
———A improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.6, FortiSOAR PaaS 7.5.0 through 7.5.3, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.6, FortiSOAR on-premise 7.5.0 through 7.5.3, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise 7.3 all versions may allow attacker to escalation of privilege via <insert attack vector here>40mCVE-2026-260849.9 CRI—
———A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to access sensitive information via crafted HTTP requests.40mCVE-2026-225754.9 MED—
———An improper access control vulnerability in Fortinet FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.10, FortiManager 7.2 all versions, FortiManager Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.4.1 through 7.4.10, FortiManager Cloud 7.2 all versions may allow an administrator to bypass the approval process for workflow sessions via crafted HTTP or HTTPs requests.40m