CVE WATCH / VULNERABILITY DETAIL
CVE-2026-104118
UNKNOWNCVSS 0NVD feed
Published 4 October 2026 · tracked since 4 October 2026
Description
The Razorpay for WooCommerce WordPress plugin before 4.8.8 does not perform ownership or authorization checks on a REST API route used during checkout, allowing unauthenticated attackers to modify the shipping information stored on arbitrary orders.
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-86817
- CVE-2026-93549
- CVE-2026-97332
- CVE-2026-17005
- CVE-2026-104119
- CVE-2026-105123 HIGH 8.8
- CVE-2026-105124 MEDIUM 6.1
- CVE-2026-105125 LOW 3.7
- CVE-2026-105118 MEDIUM 4.7
- CVE-2026-97873