CVE-2026-16739
WordPress Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-16739 is an unauthenticated order payment confirmation forgery vulnerability in the Epeken All Kurir for Woocommerce WordPress plugin. The flaw allows unauthenticated attackers to mark arbitrary WooCommerce orders as payment-confirmed — and, in non-default configurations, as fully paid — without owning the order or making any actual payment. All plugin versions through 2.1.2 are affected. It was publicly disclosed on August 12, 2026, and added to NVD on August 14, 2026. WPScan assigns a CVSS score of 5.9 (Medium), classified as CWE-287 (Improper Authentication) (WPScan, Github Advisory).

Détails techniques

The root cause is improper authentication (CWE-287 / OWASP A2: Broken Authentication and Session Management): the plugin's payment-confirmation endpoint neither validates that the requester is the order owner nor verifies that a payment transaction actually took place. An unauthenticated attacker can send a crafted HTTP request targeting any order ID to trigger the confirmation logic. In non-default plugin configurations, this also results in the order being marked as paid, bypassing the entire payment flow. No authentication token, nonce, or ownership check is enforced on the vulnerable endpoint (WPScan, Github Advisory).

Impact

Successful exploitation allows an unauthenticated attacker to manipulate the status of any WooCommerce order on an affected site, marking it as payment-confirmed without completing a real transaction. In non-default plugin configurations, orders can additionally be marked as fully paid, enabling an attacker to fraudulently obtain goods or services without payment. This directly impacts the integrity of the e-commerce order management system and can result in financial loss for store operators (WPScan, Feedly).

Exploitabilité

There is currently no public proof-of-concept exploit available; WPScan has indicated a PoC will be published on September 23, 2026, to allow time for users to update. No in-the-wild exploitation has been reported. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is reported as 0.0, reflecting low current exploitation probability (WPScan, Github Advisory).

Étapes d’exploitation

  1. Reconnaissance: Identify WordPress sites running the Epeken All Kurir for Woocommerce plugin (version ≤ 2.1.2) by scanning for the plugin's presence via common WordPress plugin enumeration techniques (e.g., checking /wp-content/plugins/epeken-all-kurir/).
  2. Identify target order: Enumerate or guess a valid WooCommerce order ID. Order IDs are often sequential integers and may be partially disclosed through order confirmation emails, URLs, or other site interactions.
  3. Craft malicious request: Send an unauthenticated HTTP request to the plugin's payment-confirmation endpoint, supplying the target order ID. No session cookie, nonce, or ownership credential is required.
  4. Trigger order status change: The plugin processes the request and marks the targeted order as payment-confirmed. In non-default configurations, the order is also marked as paid.
  5. Achieve objective: The attacker can fraudulently confirm payment for orders they did not place or pay for, potentially obtaining goods or services without completing a real transaction (WPScan).

Indicateurs de compromis

  • Logs: WooCommerce order logs or WordPress access logs showing order status changes (e.g., to processing or completed) for orders with no corresponding payment gateway transaction record; HTTP requests to the plugin's payment-confirmation endpoint originating from unexpected or unauthenticated sources.
  • Application: WooCommerce orders marked as confirmed or paid with no matching payment entry in the payment gateway dashboard or transaction history.
  • Network: Repeated or automated HTTP requests to the plugin's confirmation endpoint from a single IP or range of IPs, particularly with varying order IDs suggesting enumeration.

Atténuation et solutions de contournement

WPScan reports no known fixed version is currently available for the Epeken All Kurir for Woocommerce plugin as of the disclosure date; the advisory notes "No known fix" for the epeken-all-kurir plugin (WPScan). Store operators should consider temporarily deactivating the plugin until a patched version is released. Additionally, administrators should review recent order status changes for suspicious confirmations — particularly orders marked as paid without corresponding payment gateway records — and implement network-level controls (e.g., WAF rules) to restrict unauthenticated access to the plugin's payment-confirmation endpoint.

Réactions de la communauté

The vulnerability was discovered and reported by security researcher Pedro Pinho and verified by WPScan (WPScan). No significant broader media coverage or notable community commentary has been identified at this time, consistent with the vulnerability's medium severity and niche plugin scope.

Ressources additionnelles


SourceCe rapport a été généré à l’aide de l’IA

Apparenté WordPress Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-18039NONEN/A
  • essential-addons-for-elementor-lite
NonOuiAug 14, 2026
CVE-2026-16810NONEN/A
  • bit-form
NonOuiAug 14, 2026
CVE-2026-16739NONEN/A
  • epeken-all-kurir
NonNonAug 14, 2026
CVE-2026-15205NONEN/A
  • paymob-for-woocommerce
NonOuiAug 14, 2026
CVE-2026-14290NONEN/A
  • embed-google-photos-album-easily
NonNonAug 14, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités