CVE-2026-104118

Executive Summary

The Razorpay for WooCommerce WordPress plugin (v<4.8.8) lacks ownership/authorization checks on a REST API route used during checkout, enabling unauthenticated attackers to alter shipping information on any order. This flaw can lead to shipping fraud, privacy violations, and financial loss for merchants and customers.


Authoritative CVE Metadata - CVSS Base Score: Unknown (Unknown) - Published: 2026-10-04T07:16:31.933 - Last Modified: 2026-10-04T07:16:31.933

Original Description: The Razorpay for WooCommerce WordPress plugin before 4.8.8 does not perform ownership or authorization checks on a REST API route used during checkout, allowing unauthenticated attackers to modify the shipping information stored on arbitrary orders.

"All truths are easy to understand once they are discovered; the point is to discover them."

— Galileo Galilei
Source: NVD