SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-84043

MEDIUM · CVSS 5.3 EPSS 0.11%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The ePayco Payment Gateway for WooCommerce plugin prior to version 8.4.7 is vulnerable due to inadequate verification of payment confirmation requests, enabling unauthenticated attackers to falsely mark orders as paid. This could lead to financial losses and fraud for online merchants using this plugin. WordPress site administrators utilizing this plugin should prioritize updating to the latest version to mitigate potential exploitation.

CVE
CVE-2026-84043
Severity
MEDIUM
CVSS
5.3
EPSS
0.11%
WordPress

Original NVD Description

The ePayco Payment Gateway for WooCommerce WordPress plugin before 8.4.7 does not properly verify the authenticity of payment confirmation requests, allowing unauthenticated attackers to mark orders as paid without a valid gateway signature.