CVE-2026-97299: WordPress Razorpay Payment Links for WooCommerce plugin <= 2.1.5 - Cross Site Request Forgery (CSRF) vulnerability
Published Sep 30, 2026
·Updated
Unauthenticated Cross Site Request Forgery (CSRF) in Razorpay Payment Links for WooCommerce <= 2.1.5 versions.
Affected Software
1 affected component
Razorpay Payment Links for WooCommerce<=2.1.5
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Razorpay Payment Links for WooCommerceto a version that resolves this vulnerability.Fixed in 2.2.0
Event History
Sep 30, 2026
CVE Published
via MITRE·12:28 PM
Data Sourced
via MITRE·12:28 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
The attacker does not need to be authenticated, but exploitation requires a victim to interact with a malicious request. The CVSS vector indicates user interaction is required.
2
What versions are affected?
Razorpay Payment Links for WooCommerce versions 2.1.5 and earlier are affected.
3
What is the potential impact?
Successful exploitation can result in limited integrity and availability impact. The provided CVSS vector indicates no confidentiality impact.