CVE-2025-14843: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-14843 is an unauthenticated arbitrary order cancellation vulnerability in the Wizit Gateway for WooCommerce WordPress plugin. It affects all versions up to and including 1.2.9, and was published on January 24, 2026, with Wordfence credited as the assigner. The flaw allows any unauthenticated attacker to cancel arbitrary WooCommerce orders by sending a crafted HTTP request containing a valid order ID. It carries a CVSS v3.1 base score of 5.3 (Medium) (Wordfence, Red Hat CVE).

Technical details

The root cause is a Missing Authorization flaw (CWE-862) in the handle_checkout_redirecturl_response function of the plugin. This function processes checkout redirect URL responses without performing any authentication or authorization checks, meaning any network-accessible attacker can invoke it. By supplying a valid WooCommerce order ID in a crafted request, an attacker can trigger order cancellation for any order on the affected store. The vulnerable code is visible in the plugin's source at version 1.2.9 (Wordfence, WordPress Plugin Trac).

Impact

Successful exploitation allows an unauthenticated attacker to cancel any WooCommerce order on the affected site, directly impacting the integrity of e-commerce operations. This can result in financial disruption, order fulfillment failures, and customer dissatisfaction for affected merchants. There is no confidentiality or availability impact; the vulnerability is limited to integrity loss through unauthorized modification of order states (Wordfence).

Exploitability

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.086%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the low attack complexity and lack of authentication requirements make it straightforward to exploit if an attacker can enumerate valid order IDs (Wordfence).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Wizit Gateway for WooCommerce plugin (version ≤1.2.9) using tools like WPScan or by inspecting plugin directories on target sites.
  2. Order ID enumeration: Obtain or enumerate valid WooCommerce order IDs. Order IDs may be discoverable through order confirmation emails, publicly accessible order status pages, or sequential guessing.
  3. Craft malicious request: Construct an HTTP request targeting the handle_checkout_redirecturl_response function endpoint, including the target order ID as a parameter, without any authentication credentials.
  4. Submit request: Send the crafted request to the vulnerable WordPress site. Because no authentication or authorization check is performed, the function processes the request and cancels the specified order.
  5. Verify impact: Confirm the order has been cancelled by checking the WooCommerce order status, either through the store's order tracking page or by observing downstream effects such as cancellation emails (Wordfence, WordPress Plugin Trac).

Indicators of compromise

  • Network: Unusual or repeated HTTP requests to the WordPress site targeting the Wizit Gateway checkout redirect URL response endpoint, originating from unexpected or anonymous IP addresses.
  • Logs: WordPress or web server access logs showing POST/GET requests to the handle_checkout_redirecturl_response handler with order ID parameters from unauthenticated sessions.
  • Application: Unexpected WooCommerce order status changes to 'cancelled' for orders that were not cancelled by the customer or store administrator, particularly in bulk or rapid succession.

Mitigation and workarounds

Users should update the Wizit Gateway for WooCommerce plugin to a version beyond 1.2.9 that includes proper authentication and authorization checks in the handle_checkout_redirecturl_response function. If no patched version is yet available, site administrators should consider temporarily deactivating the plugin until a fix is released. Additionally, web application firewall (WAF) rules can be configured to restrict access to the vulnerable endpoint for unauthenticated users (Wordfence).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management