Junglewise Threat Intelligence

CVE-2026-16739: Epeken All Kurir for Woocommerce unauthenticated order confirmation forgery

CVE-2026-16739 · Severity: medium · CVSS 5.9 · Published 2026-08-14

Executive brief

Epeken All Kurir for Woocommerce is a WordPress plugin that handles shipping logistics for online stores using the Woocommerce e-commerce platform. The plugin fails to verify that payment-confirmation requests are legitimate, allowing attackers to forge order confirmations and mark arbitrary customer orders as paid without actual payment, leading to loss of revenue and fulfillment of unpaid orders.

Technical details

The vulnerability is an authentication bypass (CWE-287) in the payment-confirmation webhook handler. The plugin does not validate that payment-confirmation requests originate from the legitimate order owner or verify that payment actually occurred. An unauthenticated attacker can send a crafted HTTP request to the confirmation endpoint to mark arbitrary orders as confirmed and, depending on configuration, as paid. No authentication or user interaction is required. WPScan reports the issue affects versions through 2.1.7; the advisory title mentions through 2.1.4. No fix has been publicly identified as of the last update.

Affected products

  • Epeken All Kurir for Woocommerce through 2.1.7

Timeline

  • 2026-08-12: disclosed
  • 2026-08-11: kev added
  • 2026-09-23: other: Last updated in vulnerability database

References