PT-2026-5090 · WordPress · Rupantorpay

Published

2026-01-28

·

Updated

2026-01-28

·

CVE-2025-15511

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Rupantorpay plugin for WordPress versions through 2.0.0
Description The Rupantorpay plugin for WordPress is susceptible to unauthorized data modification. This is due to a missing capability check within the handle webhook() function. An unauthenticated attacker can exploit this to modify WooCommerce order statuses by sending specifically crafted requests to the WooCommerce API endpoint. The vulnerable function is handle webhook().
Recommendations Update the Rupantorpay plugin to a version newer than 2.0.0.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-15511

Affected Products

Rupantorpay