PT-2026-44207 · WordPress · Eupago Eupago Gateway For Woocommerce

Pedro Pinho

·

Published

2026-05-28

·

Updated

2026-05-29

·

CVE-2026-7862

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions Eupago Gateway For Woocommerce WordPress plugin versions prior to 4.7.2
Description The plugin fails to properly restrict access to its refund request handler. This allows unauthenticated attackers to initiate refunds for any WooCommerce order using the merchant's payment gateway credentials. For certain payment methods, this can be used to redirect the refunded funds to a bank account controlled by the attacker.
Recommendations Update to version 4.7.2 or later.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2026-7862

Affected Products

Eupago Eupago Gateway For Woocommerce