
PEACH
Un cadre d’isolation des locataires
CVE-2026-16739 is an unauthenticated order payment confirmation forgery vulnerability in the Epeken All Kurir for Woocommerce WordPress plugin. The flaw allows unauthenticated attackers to mark arbitrary WooCommerce orders as payment-confirmed — and, in non-default configurations, as fully paid — without owning the order or making any actual payment. All plugin versions through 2.1.2 are affected. It was publicly disclosed on August 12, 2026, and added to NVD on August 14, 2026. WPScan assigns a CVSS score of 5.9 (Medium), classified as CWE-287 (Improper Authentication) (WPScan, Github Advisory).
The root cause is improper authentication (CWE-287 / OWASP A2: Broken Authentication and Session Management): the plugin's payment-confirmation endpoint neither validates that the requester is the order owner nor verifies that a payment transaction actually took place. An unauthenticated attacker can send a crafted HTTP request targeting any order ID to trigger the confirmation logic. In non-default plugin configurations, this also results in the order being marked as paid, bypassing the entire payment flow. No authentication token, nonce, or ownership check is enforced on the vulnerable endpoint (WPScan, Github Advisory).
Successful exploitation allows an unauthenticated attacker to manipulate the status of any WooCommerce order on an affected site, marking it as payment-confirmed without completing a real transaction. In non-default plugin configurations, orders can additionally be marked as fully paid, enabling an attacker to fraudulently obtain goods or services without payment. This directly impacts the integrity of the e-commerce order management system and can result in financial loss for store operators (WPScan, Feedly).
There is currently no public proof-of-concept exploit available; WPScan has indicated a PoC will be published on September 23, 2026, to allow time for users to update. No in-the-wild exploitation has been reported. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is reported as 0.0, reflecting low current exploitation probability (WPScan, Github Advisory).
/wp-content/plugins/epeken-all-kurir/).processing or completed) for orders with no corresponding payment gateway transaction record; HTTP requests to the plugin's payment-confirmation endpoint originating from unexpected or unauthenticated sources.WPScan reports no known fixed version is currently available for the Epeken All Kurir for Woocommerce plugin as of the disclosure date; the advisory notes "No known fix" for the epeken-all-kurir plugin (WPScan). Store operators should consider temporarily deactivating the plugin until a patched version is released. Additionally, administrators should review recent order status changes for suspicious confirmations — particularly orders marked as paid without corresponding payment gateway records — and implement network-level controls (e.g., WAF rules) to restrict unauthenticated access to the plugin's payment-confirmation endpoint.
The vulnerability was discovered and reported by security researcher Pedro Pinho and verified by WPScan (WPScan). No significant broader media coverage or notable community commentary has been identified at this time, consistent with the vulnerability's medium severity and niche plugin scope.
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."