CVE-2026-104118
The Razorpay for WooCommerce WordPress plugin before 4.8.8 does not perform ownership or authorization checks on a REST API route used during checkout, allowing unauthenticated attackers to modify the shipping information stored on arbitrary orders.
- Published Oct 4, 2026
- CVSS 5.3 medium
- 0.2% chance of exploitation in the next 30 days (EPSS)
- A fix is available