THREAT OPS › Threat News › [NVD] CVE-2026-12966 — The Direct Payments for WooCommerce WordPress plugin before 2.5.3 does not verify that the requester owns the targeted WooCommerce order in several unauthenticated AJAX handlers before changing its status and overwriting its payment metadata, allowing unauthenticated attackers t
[NVD] CVE-2026-12966 — The Direct Payments for WooCommerce WordPress plugin before 2.5.3 does not verify that the requester owns the targeted WooCommerce order in several unauthenticated AJAX handlers before changing its status and overwriting its payment metadata, allowing unauthenticated attackers t
CVE-2026-12966 CVSS: None Published: 2026-08-01T07:16:28.913
The Direct Payments for WooCommerce WordPress plugin before 2.5.3 does not verify that the requester owns the targeted WooCommerce order in several unauthenticated AJAX handlers before changing its status and overwriting its payment metadata, allowing unauthenticated attackers to tamper with other customers' orders, including forging
Indicators of compromise
- CVE-2026-12966cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-12966