CVE-2026-104118: Razorpay for WooCommerce < 4.8.8 - Unauthenticated Order Shipping Modification via IDOR
Published Oct 4, 2026
·Updated
The Razorpay for WooCommerce WordPress plugin before 4.8.8 does not perform ownership or authorization checks on a REST API route used during checkout, allowing unauthenticated attackers to modify the shipping information stored on arbitrary orders.
Affected Software
1 affected component
Razorpay Razorpay for WooCommerce<4.8.8
Event History
Oct 4, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·07:16 AM
Description
Frequently Asked Questions
1
Does an attacker need a WordPress or customer account to exploit this issue?
No. The affected REST API route can be abused without authentication.
2
What can an attacker change if they exploit the vulnerable route?
They can modify the shipping information stored on arbitrary orders.
3
Which deployments are affected?
Razorpay for WooCommerce versions earlier than 4.8.8 are affected.