What is CVE-2026-13329?
The Buckaroo WooCommerce Payments Plugin before version 4.9.0 lacks capability check and nonce validation on an AJAX action for processing payment capture refunds. This flaw allows any authenticated user, including Subscribers, to trigger refunds against captured orders. Immediate update to the latest version is required.
Azərbaycanca: Buckaroo WooCommerce Payments Plugin-in 4.9.0-dan əvvəlki versiyalarında, AJAX əməliyyatı üzərində heç bir capability check və nonce validation aparılmır. Bu, autentifikasiya olunmuş istənilən istifadəçiyə, o cümlədən Subscriber roluna malik şəxslərə, tutulmuş ödənişlər üçün geri qaytarma (refund) başlatmaq imkanı verir. Plugin dərhal ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-862; shared vendor: WordPress
FAQ1
What vulnerability in the Buckaroo WooCommerce Payments Plugin allows authenticated Subscribers to initiate unauthorized refunds?
This vulnerability (CVE-2026-13329) exists because versions prior to 4.9.0 lack capability check and nonce validation on an AJAX action, allowing any authenticated user, including those with the Subscriber role, to trigger refunds against captured orders.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.