plugin

Woo Razorpay Vulnerabilities

11 known security issues reported for the Woo Razorpay WordPress plugin. Most recent disclosed Feb 19, 2026.

4 medium

Running Woo Razorpay on your site? Check whether your installed version is affected.

Scan your site free

Razorpay for WooCommerce [woo-razorpay] < 4.7.9

unknown

[en] The Razorpay for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the getCouponList() function in all versions up to, and including, 4.7.8. This is due to the checkAuthCredentials() permission callback always returning true, providing no actua...

Affected:
up to 4.7.9
Fixed in:
4.7.9
Disclosed:
Feb 19, 2026

CVE-2025-14294 on NVD →

Razorpay for WooCommerce <= 4.7.8 - Missing Authentication to Unauthenticated Order Modification

medium

The Razorpay for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the getCouponList() function in all versions up to, and including, 4.7.8. This is due to the checkAuthCredentials() permission callback always returning true, providing no actual aut...

CVSS:
5.3
Affected:
up to 4.7.8
Fixed in:
4.7.9
Disclosed:
Feb 18, 2026

CVE-2025-14294 on NVD →

Razorpay for WooCommerce <= 4.8.3 - Missing Authorization

medium

The Razorpay for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.8.3. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 4.8.3
Fixed in:
4.8.4
Disclosed:
Feb 16, 2026

CVE-2026-39656 on NVD →

Razorpay for WooCommerce <= 4.5.6 - Missing Authorization

medium

The Razorpay for WooCommerce plugin for WordPress is vulnerable to unauthorized modification due to a missing capability check on several functions hooked via admin_post in all versions up to, and including, 4.5.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to update, di...

CVSS:
4.3
Affected:
up to 4.5.6
Fixed in:
4.5.7
Disclosed:
Nov 28, 2023

Razorpay for WooCommerce <= 4.5.6 - Cross-Site Request Forgery

medium

The Razorpay for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5.6. This is due to missing nonce validation on several functions hooked via admin_post. This makes it possible for unauthenticated attackers to update, direct, create, and reverse trans...

CVSS:
4.3
Affected:
up to 4.5.6
Fixed in:
4.5.7
Disclosed:
Nov 28, 2023

Razorpay for WooCommerce [woo-razorpay] < 4.5.7

unknown

The Razorpay for WooCommerce plugin for WordPress is vulnerable to unauthorized modification due to a missing capability check on several functions hooked via admin_post in all versions up to, and including, 4.5.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to update, di...

Affected:
up to 4.5.7
Fixed in:
4.5.7
Disclosed:
Nov 28, 2023

Razorpay for WooCommerce [woo-razorpay] < 4.5.7

unknown

The Razorpay for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5.6. This is due to missing nonce validation on several functions hooked via admin_post. This makes it possible for unauthenticated attackers to update, direct, create, and reverse trans...

Affected:
up to 4.5.7
Fixed in:
4.5.7
Disclosed:
Nov 28, 2023

Razorpay for WooCommerce [woo-razorpay] < 4.5.7

unknown

Update the WordPress Razorpay for WooCommerce plugin to the latest available version (at least 4.5.7). WordFence discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Razorpay for WooCommerce Plugin. This could allow a malicious actor to force higher privileged users to execute unwan...

Affected:
up to 4.5.7
Fixed in:
4.5.7
Disclosed:
Nov 28, 2023

Razorpay for WooCommerce [woo-razorpay] < 4.5.7

unknown

Update the WordPress Razorpay for WooCommerce plugin to the latest available version (at least 4.5.7). WordFence discovered and reported this Broken Access Control vulnerability in WordPress Razorpay for WooCommerce Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token c...

Affected:
up to 4.5.7
Fixed in:
4.5.7
Disclosed:
Nov 28, 2023

Razorpay for WooCommerce [woo-razorpay] < 4.5.7

unknown

The plugin does not have authorisation checks when updating, creating and reversing transfers, which could allow any authenticated users, such as subscriber to perform such actions

Affected:
up to 4.5.7
Fixed in:
4.5.7

Razorpay for WooCommerce [woo-razorpay] < 4.5.7

unknown

The plugin does not have CSRF checks when updating, creating and reversing transfers, which could allow attackers to make logged in admins perform such actions via CSRF attacks

Affected:
up to 4.5.7
Fixed in:
4.5.7

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database