WordPress Plugin Vulnerabilities

zipMoney(Zip Co) Payments Plugin for WooCommerce < 2.4.0 - Unauthenticated Arbitrary Option Deletion

Description

The plugin does not perform any authorisation checks on one of its front-end request handlers, and does not restrict which option name a caller may supply, allowing unauthenticated users to delete arbitrary WordPress options. This can be used to destroy site and access control configuration, deactivate every installed plugin, and take the site offline.

Proof of Concept

Affects Plugins

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Naoki Kawahigashi
Submitter
Naoki Kawahigashi
Verified
Yes

Timeline

Publicly Published
2026-09-08 (about 2 days ago)
Added
2026-09-08 (about 1 day ago)
Last Updated
2026-09-09 (about 8 hours ago)

Other