PT-2026-4571 · WordPress · Wizit Gateway For Woocommerce

Published

2026-01-24

·

Updated

2026-01-24

·

CVE-2025-14843

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Wizit Gateway for WooCommerce plugin for WordPress versions up to and including 1.2.9
Description The Wizit Gateway for WooCommerce plugin for WordPress is susceptible to unauthenticated arbitrary order cancellation. This is a result of missing authentication and authorization checks within the handle checkout redirecturl response function. An attacker who is not authenticated can cancel any WooCommerce order by submitting a specially crafted request that includes a valid order ID.
Recommendations Update the Wizit Gateway for WooCommerce plugin to a version later than 1.2.9.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-14843

Affected Products

Wizit Gateway For Woocommerce