CVE-2026-16962: Tamara Checkout <= 1.9.9.20 - Unauthenticated Order Status Manipulation

Published Aug 21, 2026
·
Updated

The Tamara Checkout WordPress plugin through 1.9.9.20 does not verify the order key, a nonce, or any capability on its public payment cancel/fail return URLs, changing a WooCommerce order's status based solely on an attacker-supplied numeric order id, so an unauthenticated attacker can cancel or fail arbitrary orders store-wide by enumerating ids (triggering downstream stock-release and notification side-effects).

Affected Software

1 affected component
WordPress plugin Tamara Checkout<=1.9.9.20

Event History

Aug 21, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any unauthenticated remote attacker can exploit it. No WordPress account, WooCommerce permission, order key, or nonce is required.

2

What orders are at risk?

Arbitrary WooCommerce orders across the store may be targeted if an attacker can supply or enumerate their numeric order IDs. Successful requests can set orders to cancelled or failed.

3

What operational effects can exploitation cause?

Changing an order status can trigger downstream stock-release and notification side effects. This can disrupt fulfillment and generate customer or administrator notifications.

4

How can I determine whether my site is affected?

Sites using the Tamara Checkout WordPress plugin through version 1.9.9.20 are affected. Review WooCommerce order histories for unexpected cancellations or failures, particularly involving multiple or sequential order IDs.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203