PayU CommercePro Plugin <= 3.8.9 - Missing Authorization
medium
The PayU CommercePro Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.8.9. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 3.8.9
- Fixed in:
- 3.9.0
- Disclosed:
- Jul 22, 2026
CVE-2026-61954 on NVD →
PayU CommercePro < 3.9.0 - Missing Authorization
medium
The PayU CommercePro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and excluding, 3.9.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 3.9.0
- Fixed in:
- 3.9.0
- Disclosed:
- Jul 7, 2026
CVE-2026-13692 on NVD →
PayU CommercePro Plugin <= 3.8.7 - Authentication Bypass
critical
The PayU CommercePro Plugin plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 3.8.7. This is due to the plugin not properly verifying a user's identity through the update_cart_data() function. This makes it possible for unauthenticated attackers to log in as an administra...
- CVSS:
- 9.8
- Affected:
- up to 3.8.7
- Fixed in:
- 3.8.8
- Disclosed:
- Jun 5, 2025
CVE-2025-31022 on NVD →
PayU CommercePro Plugin <= 3.8.3 - Unauthenticated Privilege Escalation
critical
The PayU CommercePro Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.8.3. This is due to /wp-json/payu/v1/generate-user-token and /wp-json/payu/v1/get-shipping-cost REST API endpoints not properly verifying a user's identity prior to setting the users ID and au...
- CVSS:
- 9.8
- Affected:
- up to 3.8.3
- Fixed in:
- 3.8.4
- Disclosed:
- Jan 6, 2025
CVE-2024-12264 on NVD →
PayU India <= 3.8.8 - Reflected Cross-Site Scripting via type
medium
The PayU India plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘type’ parameter in versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if t...
- CVSS:
- 6.1
- Affected:
- up to 3.8.8
- Fixed in:
- 3.8.9
- Disclosed:
- Feb 26, 2024
CVE-2024-27193 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database