CVE-2026-74009: WordPress Razorpay for WooCommerce plugin <= 4.8.7 - Insecure Direct Object References (IDOR) vulnerability
Published Aug 18, 2026
·Updated
Unauthenticated Insecure Direct Object References (IDOR) in Razorpay for WooCommerce <= 4.8.7 versions.
Affected Software
1 affected component
Razorpay Razorpay for WooCommerce<=4.8.7
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Razorpay for WooCommerceto a version that resolves this vulnerability.Fixed in 4.8.7
Event History
Aug 18, 2026
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which versions are affected?
The affected product is Razorpay for WooCommerce, with versions up to and including 4.8.7 identified as vulnerable.
2
What access does an attacker need to exploit this issue?
The vulnerability is unauthenticated, and the vector is network-accessible. An attacker does not need prior privileges or user interaction to exploit the affected functionality.
3
What is the expected security impact?
The provided severity vector indicates integrity impact only, with no listed confidentiality or availability impact. The issue is rated medium with a CVSS score of 5.3.