SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-16739

MEDIUM · CVSS 5.9 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-08-14 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

The Epeken All Kurir for WooCommerce plugin for WordPress versions up to 2.1.2 is vulnerable due to a lack of verification for payment-confirmation requests, enabling unauthenticated attackers to falsely mark any order as confirmed and potentially paid. This could lead to significant financial losses and order management issues for affected e-commerce sites. WordPress site administrators using this plugin should prioritize immediate updates or mitigations to protect against unauthorized order manipulations.

CVE
CVE-2026-16739
Severity
MEDIUM
CVSS
5.9
EPSS
0.22%
WordPress

Original NVD Description

The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.4 does not verify that a payment-confirmation request originates from the owner of the targeted order, nor that any payment actually occurred, allowing unauthenticated attackers to mark arbitrary orders as confirmed and, in a non-default configuration, paid.