Netcash WooCommerce Payment Gateway <= 4.1.3 - Missing Authorization to Unauthenticated Order Status Modification
mediumThe Netcash WooCommerce Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the handle_return_url function in all versions up to, and including, 4.1.3. This makes it possible for unauthenticated attackers to mark any WooCommerce order as processin...
- CVSS:
- 5.3
- Affected:
- up to 4.1.3
- Fixed in:
- 4.1.4
- Disclosed:
- Jan 13, 2026