WordPress Plugin Vulnerabilities

Tamara Checkout <= 1.9.9.20 - Unauthenticated Order Status Manipulation

Description

The plugin does not verify the order key, a nonce, or any capability on its public payment cancel/fail return URLs, changing a WooCommerce order's status based solely on an attacker-supplied numeric order id, so an unauthenticated attacker can cancel or fail arbitrary orders store-wide by enumerating ids (triggering downstream stock-release and notification side-effects).

Proof of Concept

Affects Plugins

No known fix

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Ezekiel Victor
Submitter
Ezekiel Victor
Verified
Yes

Timeline

Publicly Published
2026-08-18 (about 2 days ago)
Added
2026-08-11 (about 9 days ago)
Last Updated
2026-08-11 (about 9 days ago)

Other