Executive brief
The Razorpay for WooCommerce plugin, which enables businesses to accept payments on their WordPress websites, contains a security flaw in its access control settings. This vulnerability could allow an unauthorized individual to perform actions that should be restricted to administrators or specific users. While the impact is limited, it could lead to unauthorized changes in the store's configuration or payment processing flow.
Technical details
A Missing Authorization (CWE-862) vulnerability exists in the Razorpay for WooCommerce plugin (woo-razorpay) through version 4.8.3. The flaw stems from a failure to properly validate user permissions or implement sufficient nonce checks on certain functions, leading to broken access control. An unauthenticated remote attacker can exploit this to execute actions that should require higher privilege levels. The vulnerability is addressed in version 4.8.4. According to the CVSS vector, the primary impact is on integrity (Partial), with no direct impact on confidentiality or availability.
Affected products
- Razorpay Razorpay for WooCommerce (woo-razorpay) <= 4.8.3
Timeline
- 2026-01-17: other: Vulnerability reported by Nguyen Ba Khanh
- 2026-02-16: disclosed: Initial disclosure by Patchstack
- 2026-04-08: advisory: CVE published to NVD
- 2026-04-08: patched: Patch available in version 4.8.4