CVE-2026-14830: The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout session was actually... (CVSS 7.5)

The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout session was actually paid before marking the associated order as paid, allowing unauthenticated attackers to complete WooCommerce orders without paying.

Vulners1 min read
Read full article
CVE-2026-14830: The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout session was actually... (CVSS 7.5)

Read the full story at Vulners →