
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14843 is an unauthenticated arbitrary order cancellation vulnerability in the Wizit Gateway for WooCommerce WordPress plugin. It affects all versions up to and including 1.2.9, and was published on January 24, 2026, with Wordfence credited as the assigner. The flaw allows any unauthenticated attacker to cancel arbitrary WooCommerce orders by sending a crafted HTTP request containing a valid order ID. It carries a CVSS v3.1 base score of 5.3 (Medium) (Wordfence, Red Hat CVE).
The root cause is a Missing Authorization flaw (CWE-862) in the handle_checkout_redirecturl_response function of the plugin. This function processes checkout redirect URL responses without performing any authentication or authorization checks, meaning any network-accessible attacker can invoke it. By supplying a valid WooCommerce order ID in a crafted request, an attacker can trigger order cancellation for any order on the affected store. The vulnerable code is visible in the plugin's source at version 1.2.9 (Wordfence, WordPress Plugin Trac).
Successful exploitation allows an unauthenticated attacker to cancel any WooCommerce order on the affected site, directly impacting the integrity of e-commerce operations. This can result in financial disruption, order fulfillment failures, and customer dissatisfaction for affected merchants. There is no confidentiality or availability impact; the vulnerability is limited to integrity loss through unauthorized modification of order states (Wordfence).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.086%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the low attack complexity and lack of authentication requirements make it straightforward to exploit if an attacker can enumerate valid order IDs (Wordfence).
handle_checkout_redirecturl_response function endpoint, including the target order ID as a parameter, without any authentication credentials.handle_checkout_redirecturl_response handler with order ID parameters from unauthenticated sessions.Users should update the Wizit Gateway for WooCommerce plugin to a version beyond 1.2.9 that includes proper authentication and authorization checks in the handle_checkout_redirecturl_response function. If no patched version is yet available, site administrators should consider temporarily deactivating the plugin until a fix is released. Additionally, web application firewall (WAF) rules can be configured to restrict access to the vulnerable endpoint for unauthenticated users (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."