What is CVE-2026-13692?
CVE-2026-13692 is a critical vulnerability in the PayU CommercePro Plugin for WordPress up to version 3.8.9. It fails to verify the payment gateway signature before modifying orders, enabling unauthenticated attackers to alter the totals, shipping, and metadata of arbitrary WooCommerce orders. Immediate plugin update is required.
Azərbaycanca: CVE-2026-13692, PayU CommercePro Plugin (WordPress) üçün kritik bir zəiflikdir. 3.8.9 və daha əvvəlki versiyalarda, plugin ödəniş qapısı imzasını yoxlamadığı üçün təsdiqlənməmiş hücumçular WooCommerce sifarişlərinin cəmi, çatdırılma və metadata məlumatlarını dəyişdirə bilər. Plugin-i dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
Which versions of the PayU CommercePro Plugin are affected by CVE-2026-13692?
The vulnerability affects versions up to and including 3.8.9.
What can an attacker modify in WooCommerce orders by exploiting this vulnerability?
They can alter order totals, shipping, and metadata.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.