WordPress Plugin Vulnerabilities

UPI QR Code Payment Gateway <= 1.4.3 - Unauthenticated Cross-Order Payment-Status Forgery

Description

The plugin does not verify that a payment-confirmation request actually belongs to the order and customer it claims to confirm, allowing unauthenticated attackers to mark an arbitrary order as paid without making any payment.

Proof of Concept

Affects Plugins

References

Classification

Type
IDOR
CWE

Miscellaneous

Original Researcher
Pedro Pinho
Submitter
Pedro Pinho
Verified
Yes

Timeline

Publicly Published
2026-10-02 (about 2 days ago)
Added
2026-09-25 (about 9 days ago)
Last Updated
2026-09-25 (about 9 days ago)

Other