CVE-2026-10599: Integrate PhonePe with WooCommerce <= 1.2.1 - Unauthenticated Payment Bypass via Transaction ID Reuse
The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not validate that a verified payment transaction belongs to the order being marked as paid, nor does it verify the authenticity of its payment-completion request, allowing unauthenticated attackers to reuse a single valid transaction to mark arbitrary orders as paid and bypass payment.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10599?
CVE-2026-10599 has a severity rating of high, specifically a score of 7.5.
How do I fix CVE-2026-10599?
To fix CVE-2026-10599, update the Integrate PhonePe with WooCommerce plugin to the latest version that addresses this vulnerability.
What kind of attack does CVE-2026-10599 allow?
CVE-2026-10599 allows unauthenticated attackers to bypass payment authentication by reusing a valid transaction ID.
What are the risks associated with CVE-2026-10599?
The risks include potential financial loss and unauthorized orders being processed without proper payment verification.
Which plugin is affected by CVE-2026-10599?
CVE-2026-10599 affects the Integrate PhonePe with WooCommerce plugin version 1.2.1 and below.