CVE-2026-97299

Unauthenticated Cross Site Request Forgery (CSRF) in Razorpay Payment Links for WooCommerce <= 2.1.5 versions.

  • Published Sep 30, 2026
  • CVSS 5.4 medium
  • 0.1% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-97299 at the National Vulnerability Database