CVE-2026-84169: UPI QR Code Payment Gateway <= 1.4.3 - Unauthenticated Cross-Order Payment-Status Forgery
The UPI QR Code Payment Gateway WordPress plugin through 1.4.3 does not verify that a payment-confirmation request actually belongs to the order and customer it claims to confirm, allowing unauthenticated attackers to mark an arbitrary order as paid without making any payment.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Sites using the UPI QR Code Payment Gateway WordPress plugin through version 1.4.3 are exposed. An attacker can target arbitrary orders handled by the affected plugin.
What does an attacker need to exploit it?
The flaw can be exploited without authentication. The attacker does not need to make a payment, because payment-confirmation requests are not verified against the claimed order and customer.
What is the impact of successful exploitation?
An attacker can cause an arbitrary order to be marked as paid. This can result in goods, services, or order fulfillment being released without a legitimate payment.