CVE-2026-16739
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-16739 is an unauthenticated order payment confirmation forgery vulnerability in the Epeken All Kurir for WooCommerce WordPress plugin. The flaw affects all versions through 2.1.2 and allows unauthenticated attackers to mark arbitrary orders as confirmed — and in non-default configurations, as paid — without verifying request origin or actual payment. It was publicly disclosed on August 12, 2026, with the CVE published on August 14, 2026. The vulnerability carries a CVSS v3.1 base score of 5.9 (Medium) (WPScan, Github Advisory).

Technical details

The root cause is improper authentication (CWE-287): the plugin's payment-confirmation endpoint does not validate that the incoming request originates from the legitimate order owner, nor does it confirm that a real payment transaction occurred. An unauthenticated attacker can craft an HTTP request targeting any order ID and submit it to the payment-confirmation handler, causing WooCommerce to update the order status without any authorization check. In non-default plugin configurations, this also results in the order being marked as paid. The vulnerability was discovered and reported by researcher Pedro Pinho, with a proof-of-concept scheduled for public release on September 23, 2026 (WPScan).

Impact

Successful exploitation allows an unauthenticated attacker to manipulate the status of any WooCommerce order on an affected store, marking it as payment-confirmed without actual payment. In non-default plugin configurations, orders can also be marked as fully paid, enabling fraudulent order fulfillment and direct financial loss to merchants. There is no confidentiality or availability impact; the risk is entirely to data integrity and business logic, with potential for significant financial fraud at scale across affected WooCommerce stores (WPScan, Github Advisory).

Exploitability

No public proof-of-concept exploit is currently available; WPScan has scheduled PoC disclosure for September 23, 2026, to allow time for users to update. There is no evidence of in-the-wild exploitation at this time, and CISA's SSVC assessment classifies exploitation as "none" and the vulnerability as not automatable. The EPSS score is approximately 0.147–0.221%, placing it in the 13th percentile for exploitation likelihood (WPScan, Github Advisory).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Epeken All Kurir for WooCommerce plugin (version ≤ 2.1.2) by scanning for plugin-specific file paths (e.g., /wp-content/plugins/epeken-all-kurir/) or using tools like WPScan.
  2. Identify target orders: Enumerate or guess WooCommerce order IDs, which are typically sequential integers accessible via public order confirmation pages or by placing a test order.
  3. Craft malicious request: Construct an HTTP request to the plugin's payment-confirmation endpoint, supplying the target order ID without any authentication token or payment proof.
  4. Submit request: Send the crafted request to the vulnerable endpoint; the plugin processes it without verifying the requester's identity or confirming payment occurred.
  5. Order status manipulation: The targeted order is marked as payment-confirmed (and potentially paid in non-default configurations), enabling fraudulent fulfillment of goods or services without actual payment (WPScan).

Indicators of compromise

  • Network: Unexpected HTTP POST/GET requests to the Epeken All Kurir plugin's payment-confirmation endpoint from unauthenticated or unknown IP addresses; high volume of requests targeting multiple order IDs in rapid succession.
  • Logs: WordPress/WooCommerce access logs showing payment-confirmation requests without corresponding payment gateway callback entries; order status changes to "confirmed" or "paid" with no matching payment transaction records in the payment gateway.
  • Application: WooCommerce orders showing status transitions to "processing" or "completed" without associated payment gateway transaction IDs; orders marked as paid with no revenue recorded in payment processor dashboards.

Mitigation and workarounds

The WPScan advisory notes there is no known fix available for the plugin as of the disclosure date, and the plugin currently has no patched version listed. Store owners should consider deactivating and removing the Epeken All Kurir for WooCommerce plugin until a patched version is released. As an interim measure, administrators should review recent order status changes for suspicious confirmations lacking corresponding payment records, and consider implementing web application firewall (WAF) rules to block unauthenticated requests to the plugin's payment-confirmation endpoint (WPScan, Github Advisory).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-19848MEDIUM6.5
  • wp-user-avatar
NoYesAug 21, 2026
CVE-2026-17559MEDIUM5.3
  • content-protector
NoYesAug 21, 2026
CVE-2026-16650MEDIUM5.3
  • charitable
NoYesAug 21, 2026
CVE-2026-15150MEDIUM5.3
  • mycred
NoYesAug 21, 2026
CVE-2026-18356LOW3.7
  • limit-login-attempts-reloaded
NoYesAug 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management