What is CVE-2026-16739?
This vulnerability affects the 'Epeken All Kurir for Woocommerce' WordPress plugin up to version 2.1.2. Due to missing verification, unauthenticated attackers can mark arbitrary orders as confirmed without actual payment. Users should urgently update the plugin or implement additional authentication checks.
Azərbaycanca: Bu boşluq "Epeken All Kurir for Woocommerce" WordPress plugin-inin 2.1.2 versiyasına qədər olan bütün versiyalarına təsir edir. Doğrulama olmaması səbəbindən autentifikasiya olunmamış hücumçular istənilən sifarişi ödənilmiş kimi qeyd edə bilər. Plugin istifadəçiləri təcili olaraq yeniləməni tətbiq etməli və ya əlavə autentifikasiya mexanizmləri əlavə etməlidir.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
Which WordPress plugin is affected by the CVE-2026-16739 vulnerability?
The ‘Epeken All Kurir for Woocommerce’ plugin, all versions up to 2.1.2.
What can an attacker achieve by exploiting this vulnerability?
They can mark arbitrary orders as confirmed without actual payment, without authentication.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.