WordPress Plugin Vulnerabilities

Epeken All Kurir <= 2.1.2 - Unauthenticated Order Payment Confirmation Forgery

Description

The plugin does not verify that a payment-confirmation request originates from the owner of the targeted order, nor that any payment actually occurred, allowing unauthenticated attackers to mark arbitrary orders as confirmed and, in a non-default configuration, paid.

Proof of Concept

Affects Plugins

No known fix

References

Classification

Miscellaneous

Original Researcher
Pedro Pinho
Submitter
Pedro Pinho
Verified
Yes

Timeline

Publicly Published
2026-08-12 (about 2 days ago)
Added
2026-08-11 (about 2 days ago)
Last Updated
2026-08-13 (about 23 hours ago)

Other