What is CVE-2026-12966?
The Direct Payments for WooCommerce WordPress plugin before version 2.5.3 lacks ownership verification on targeted WooCommerce orders in several unauthenticated AJAX handlers. This vulnerability allows unauthenticated attackers to tamper with other customers' order statuses and overwrite payment metadata. Updating the plugin to at least version 2.5.3 is strongly recommended.
Azərbaycanca: Direct Payments for WooCommerce WordPress plaqininin 2.5.3-dən əvvəlki versiyalarında autentifikasiya olunmamış AJAX sorğularında hədəf sifarişin sahibliyini yoxlamamaq boşluğu mövcuddur. Bu zəiflik autentifikasiya olunmamış hücumçulara digər müştərilərin WooCommerce sifariş statuslarını dəyişməyə və ödəniş məlumatlarını manipulə etməyə imkan verir. Plaqini ən azı 2.5.3 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which WordPress plugin is affected by CVE-2026-12966?
This vulnerability affects the Direct Payments for WooCommerce plugin before version 2.5.3.
What can an unauthenticated attacker achieve by exploiting CVE-2026-12966?
An unauthenticated attacker can tamper with other customers' order statuses and overwrite payment metadata.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.