CVE-2026-16739: Epeken All Kurir <= 2.1.2 - Unauthenticated Order Payment Confirmation Forgery
The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.2 does not verify that a payment-confirmation request originates from the owner of the targeted order, nor that any payment actually occurred, allowing unauthenticated attackers to mark arbitrary orders as confirmed and, in a non-default configuration, paid.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16739?
CVE-2026-16739 has a risk score of 72, indicating a significant security vulnerability.
How do I fix CVE-2026-16739?
To fix CVE-2026-16739, update the Epeken All Kurir for Woocommerce WordPress plugin to version 2.1.3 or later.
What does CVE-2026-16739 allow an attacker to do?
CVE-2026-16739 allows unauthenticated attackers to forge payment confirmation requests for arbitrary orders.
Which plugin is affected by CVE-2026-16739?
CVE-2026-16739 affects the Epeken All Kurir for Woocommerce WordPress plugin up to version 2.1.2.
When was CVE-2026-16739 published?
CVE-2026-16739 was published on August 14, 2026.