Vulnerability Description
The PayU CommercePro Plugin WordPress plugin through 3.8.9 does not verify the payment-gateway signature before applying order modifications, allowing unauthenticated attackers to tamper with the totals, shipping and metadata of arbitrary WooCommerce orders.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-13692?
CVE-2026-13692 is a vulnerability with a CVSS score of 5.3 (MEDIUM). The PayU CommercePro Plugin WordPress plugin through 3.8.9 does not verify the payment-gateway signature before applying order modifications, allowing unauthenticated attackers to tamper with the tota...
How severe is CVE-2026-13692?
CVE-2026-13692 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-13692?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.