SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-13692

MEDIUM · CVSS 5.3 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

The PayU CommercePro Plugin for WordPress versions up to 3.8.9 is vulnerable due to a lack of signature verification for payment-gateway transactions, enabling unauthenticated attackers to manipulate order totals, shipping details, and metadata in WooCommerce. This flaw poses a risk of financial fraud and data integrity issues for e-commerce operations. WordPress site administrators using this plugin should prioritize patching to mitigate potential exploitation.

CVE
CVE-2026-13692
Severity
MEDIUM
CVSS
5.3
EPSS
0.18%
WordPress

Original NVD Description

The PayU CommercePro Plugin WordPress plugin before 3.9.0 does not verify the payment-gateway signature before applying order modifications, allowing unauthenticated attackers to tamper with the totals, shipping and metadata of arbitrary WooCommerce orders.