CVE-2026-39656: WordPress Razorpay for WooCommerce plugin <= 4.8.2 - Broken Access Control vulnerability
Missing Authorization vulnerability in Razorpay Razorpay for WooCommerce woo-razorpay allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Razorpay for WooCommerce: from n/a through <= 4.8.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Razorpay for WooCommerce (woo-razorpay)to a version that resolves this vulnerability.Fixed in 4.8.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-39656?
CVE-2026-39656 has a medium severity rating of 5.3 according to the CVSS 3.1 scoring system.
How do I fix CVE-2026-39656?
To fix CVE-2026-39656, update the Razorpay for WooCommerce plugin to the latest version above 4.8.2.
What are the potential impacts of exploiting CVE-2026-39656?
Exploiting CVE-2026-39656 can lead to improperly configured access controls, allowing unauthorized users to gain access to sensitive functions.
Which versions of the Razorpay for WooCommerce plugin are affected by CVE-2026-39656?
CVE-2026-39656 affects all versions of the Razorpay for WooCommerce plugin up to and including 4.8.2.
Is CVE-2026-39656 a critical vulnerability?
CVE-2026-39656 is classified as a medium severity vulnerability, not critical, but should still be addressed promptly.