CVE-2025-14843
The Wizit Gateway for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Arbitrary Order Cancellation in all versions up to,
CVSS
5.3
Medio
EPSS
0.4%
p35
KEV
—
Exploit Today
10
0-100
Publicado: 24 ene 2026 · Última mod.: 6 ago 2026 · CWE-862
0.4%EPSS · 30 días0.4%
2026-08-252026-09-23
The Wizit Gateway for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Arbitrary Order Cancellation in all versions up to, and including, 1.3.1. This is due to a lack of authentication and authorization checks in the 'handle_checkout_redirecturl_response' function. This makes it possible for unauthenticated attackers to cancel arbitrary WooCommerce orders by sending a crafted request with a valid order ID.
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/wizit-gateway-for-woocommerce/tags/1.2.9/class-wizit-gateway.php?marks=1249,1341-1349#L1249
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/changeset/3474107/wizit-gateway-for-woocommerce
- www.wordfence.comhttps://www.wordfence.com/threat-intel/vulnerabilities/id/b6926c2c-79d4-477c-a2eb-ba62545f2e2b?source=cve
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-956047.5 ALT—
——0Unauthenticated Broken Access Control in Loops & Logic <= 4.2.4 versions.4hCVE-2026-955276.5 MED—
——0Unauthenticated Broken Access Control in Conekta Payment Gateway <= 6.2.4 versions.4hCVE-2026-955137.5 ALT—
——0Unauthenticated Broken Access Control in Online Booking & Scheduling Calendar for WordPress by vcita <= 4.6.0 versions.4hCVE-2026-946795.4 MED—
——0Subscriber Broken Access Control in Fluent Support <= 2.3.2 versions.4hCVE-2026-944986.5 MED—
——0Unauthenticated Broken Access Control in AppMySite <= 3.15.4 versions.4hCVE-2026-940805.3 MED—
——0Unauthenticated Broken Access Control in MarketKing <= 2.1.70 versions.4h