CVE-2026-104118
EUVD-2026-9207204.10.2026, 07:16
The Razorpay for WooCommerce WordPress plugin before 4.8.8 does not perform ownership or authorization checks on a REST API route used during checkout, allowing unauthenticated attackers to modify the shipping information stored on arbitrary orders.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.