SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-74009

MEDIUM · CVSS 5.3 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-08-18 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Razorpay for WooCommerce versions up to 4.8.7 are vulnerable to unauthenticated Insecure Direct Object References (IDOR), allowing attackers to access sensitive resources without proper authorization. This could lead to unauthorized data exposure or manipulation, impacting the integrity and confidentiality of user transactions. E-commerce platforms utilizing this plugin should prioritize remediation to safeguard customer data and maintain compliance.

CVE
CVE-2026-74009
Severity
MEDIUM
CVSS
5.3
EPSS
0.28%

Original NVD Description

Unauthenticated Insecure Direct Object References (IDOR) in Razorpay for WooCommerce <= 4.8.7 versions.