CVE WATCH / VULNERABILITY DETAIL
CVE-2026-84169
UNKNOWNCVSS 0NVD feed
Published 5 October 2026 · tracked since 5 October 2026
Description
The UPI QR Code Payment Gateway WordPress plugin through 1.4.3 does not verify that a payment-confirmation request actually belongs to the order and customer it claims to confirm, allowing unauthenticated attackers to mark an arbitrary order as paid without making any payment.
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-13607
- CVE-2026-78371
- CVE-2026-105231 HIGH 7.3
- CVE-2026-105232 HIGH 7.3
- CVE-2026-105233 MEDIUM 6.3
- CVE-2026-105230 HIGH 7.3
- CVE-2026-105226 MEDIUM 4.7
- CVE-2026-105229 HIGH 7.3
- CVE-2026-105188 LOW 3.5
- CVE-2026-105225 MEDIUM 4.3