PT-2026-67026 · WordPress · Buckaroo Woocommerce Payments Plugin
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Buckaroo Woocommerce Payments Plugin versions prior to 4.9.0
Description
An issue exists where the plugin fails to perform capability checks or nonce validation—a security mechanism used to prevent cross-site request forgery—on an AJAX action used to process payment capture refunds. This allows any authenticated user, including those with Subscriber privileges, to trigger refunds for captured orders.
Recommendations
Update the plugin to version 4.9.0 or later.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Buckaroo Woocommerce Payments Plugin