CVE-2026-12973: PayPlus Payment Gateway < 8.2.2 - Unauthenticated Order Key Disclosure and Order Status Modification
The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to disclose the secret order key of arbitrary WooCommerce orders and, under some configurations, to modify order statuses.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PayPlus Payment Gateway (WordPress plugin)to a version that resolves this vulnerability.Fixed in 8.2.2 - Compensating control
Until upgraded, block unauthenticated access to the PayPlus Payment Gateway WooCommerce plugin AJAX endpoint(s) that allow order key disclosure and (under some configurations) order status modification.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12973?
CVE-2026-12973 has a medium severity rating of 6.5 according to the CVSS 3.1 scoring system.
How do I fix CVE-2026-12973?
To fix CVE-2026-12973, update the PayPlus Payment Gateway plugin to version 8.2.2 or later.
What impact does CVE-2026-12973 have on my WooCommerce store?
CVE-2026-12973 allows unauthenticated users to disclose sensitive order keys and potentially modify order statuses.
Who is affected by CVE-2026-12973?
CVE-2026-12973 affects all users of the PayPlus Payment Gateway WordPress plugin prior to version 8.2.2.
Is authentication required to exploit CVE-2026-12973?
No, CVE-2026-12973 can be exploited by unauthenticated users, making it a serious concern.