
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14294 is a missing authentication vulnerability in the Razorpay for WooCommerce plugin for WordPress that allows unauthenticated attackers to modify order contact information. The flaw affects all versions of the plugin up to and including 4.7.8. It was published on February 19, 2026, and carries a CVSS v3.1 base score of 5.3 (Medium) (Red Hat CVE).
The root cause is a broken permission callback in the plugin's REST API: the checkAuthCredentials() function, used as the permission callback for the getCouponList() endpoint, unconditionally returns true, effectively bypassing all authentication checks (CWE-306: Missing Authentication for Critical Function). Because no capability check is enforced, any unauthenticated network request can reach the endpoint. An attacker who knows or can guess a WooCommerce order ID can send a crafted request to modify the billing and shipping contact details (email and phone number) associated with that order (Red Hat CVE).
Successful exploitation allows an unauthenticated remote attacker to tamper with the billing and shipping contact information (email address and phone number) of any WooCommerce order, impacting data integrity. While confidentiality and availability are not directly affected, order hijacking could facilitate fraud, redirect order communications, or disrupt customer notifications. The scope is limited to WooCommerce order metadata on sites running the vulnerable plugin (Red Hat CVE).
No public proof-of-concept exploit code or active in-the-wild exploitation has been reported as of the available data. The EPSS score is approximately 0.091%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires only knowledge or enumeration of a valid WooCommerce order ID, which lowers the practical barrier for opportunistic attackers (Red Hat CVE).
getCouponList() function, including the target order ID and desired replacement contact values (email and/or phone) as parameters.checkAuthCredentials() returns true unconditionally, the server processes the request without authentication and updates the billing/shipping contact information for the specified order./wp-json/razorpay/v1/getCouponList or similar) from unexpected or anonymous sources.Site administrators should update the Razorpay for WooCommerce plugin to a version beyond 4.7.8 that includes a corrected checkAuthCredentials() permission callback. Until a patched version is available or applied, consider disabling the plugin or restricting access to the WordPress REST API for unauthenticated users via a web application firewall (WAF) rule or server-level configuration. Monitoring WooCommerce order records for unexpected contact information changes is also recommended as a detective control (Red Hat CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."