WordPress Plugin Vulnerabilities

FlxWoo < 3.1.1 - Unauthenticated Payment Bypass

Description

The plugin does not verify with the payment processor that a checkout session was actually paid before marking the associated order as paid, allowing unauthenticated attackers to complete WooCommerce orders without paying.

Proof of Concept

Affects Plugins

Fixed in 3.1.1

References

Classification

Miscellaneous

Original Researcher
Pedro Pinho
Submitter
Pedro Pinho
Verified
Yes

Timeline

Publicly Published
2026-07-13 (about 18 days ago)
Added
2026-07-13 (about 17 days ago)
Last Updated
2026-07-13 (about 17 days ago)

Other