Executive brief
The Tamara Checkout WordPress plugin fails to verify user identity or permissions when processing payment cancellation and failure callbacks, allowing unauthenticated attackers to change the status of arbitrary customer orders by simply guessing order IDs. This can disrupt order fulfillment, trigger automatic stock refunds, and send false notification emails to customers, undermining store operations and customer confidence.
Technical details
The plugin's payment callback handlers (`tamara-payment-cancel` and `tamara-payment-fail` endpoints) perform order status updates without validating the order key, nonce, or user capabilities. An attacker can craft simple GET requests with an arbitrary numeric `wcOrderId` parameter to transition processing orders to cancelled or failed states. The vulnerability is unauthenticated and requires no user interaction; an attacker can enumerate sequential order IDs to manipulate multiple orders store-wide. Exploitation triggers downstream effects including automatic stock release and customer notification emails.
Affected products
- Tamara Checkout through 1.9.9.23
Timeline
- 2026-08-18: disclosed
- 2026-08-11: advisory