CVE WATCH / VULNERABILITY DETAIL

CVE-2026-84169

UNKNOWNCVSS 0NVD feed

Published 5 October 2026 · tracked since 5 October 2026

Description

The UPI QR Code Payment Gateway WordPress plugin through 1.4.3 does not verify that a payment-confirmation request actually belongs to the order and customer it claims to confirm, allowing unauthenticated attackers to mark an arbitrary order as paid without making any payment.

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-84169 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-84169

UNKNOWNCVSS 0NVD feed

Published 5 October 2026 · tracked since 5 October 2026

Description

The UPI QR Code Payment Gateway WordPress plugin through 1.4.3 does not verify that a payment-confirmation request actually belongs to the order and customer it claims to confirm, allowing unauthenticated attackers to mark an arbitrary order as paid without making any payment.

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]