The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.2 does not verify that a payment-confirmation request originates from the owner of the targeted order, nor that any payment actually occurred, allowing unauthenticated attackers to mark arbitrary orders as confirmed and, in a non-default configuration, paid.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 14 Aug 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 |
Fri, 14 Aug 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.2 does not verify that a payment-confirmation request originates from the owner of the targeted order, nor that any payment actually occurred, allowing unauthenticated attackers to mark arbitrary orders as confirmed and, in a non-default configuration, paid. | |
| Title | Epeken All Kurir <= 2.1.2 - Unauthenticated Order Payment Confirmation Forgery | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-14T06:00:11.497Z
Reserved: 2026-07-23T08:17:21.130Z
Link: CVE-2026-16739
No data.
Status : Received
Published: 2026-08-14T06:17:03.153
Modified: 2026-08-14T06:17:03.153
Link: CVE-2026-16739
No data.
OpenCVE Enrichment
Updated: 2026-08-14T07:30:17Z
Weaknesses