What is CVE-2026-10599?
CVE-2026-10599: An authentication bypass vulnerability in the 'Integrate PhonePe with WooCommerce' WordPress plugin allows unauthenticated attackers to mark orders as paid by reusing a single valid transaction. Affecting versions up to 1.2.1, it fails to verify transaction ownership and request authenticity. Users must update or disable the plugin immediately.
Azərbaycanca: CVE-2026-10599: 'Integrate PhonePe with WooCommerce' WordPress pluginində autentifikasiya zəifliyi aşkarlanıb. Bu qüsur autentifikasiya olunmamış hücumçulara tək bir etibarlı əməliyyatı təkrar istifadə edərək sifarişləri ödənilmiş kimi göstərməyə imkan verir. Plugin 1.2.1 versiyasına qədər təsirlənir; istifadəçilər dərhal yeniləməli və ya müvəqqəti olaraq deaktiv etməlidir.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
What does the CVE-2026-10599 vulnerability in the 'Integrate PhonePe with WooCommerce' plugin allow attackers to do?
The vulnerability allows unauthenticated attackers to mark WooCommerce orders as paid by reusing a single valid transaction.
Which versions of the 'Integrate PhonePe with WooCommerce' plugin are affected by CVE-2026-10599?
The vulnerability affects all versions of the plugin up to 1.2.1.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.