Back to CVE List

CVE-2026-14830

Vulnerability Description

The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout session was actually paid before marking the associated order as paid, allowing unauthenticated attackers to complete WooCommerce orders without paying.

Vulnerability Details

Published Date
Last Modified
Source
NVD
Vendor
Unknown
Product
FlxWoo

External References

Discussion (0)

Add Comment

No comments yet. Be the first!