Executive brief
The UPI QR Code Payment Gateway for WooCommerce, a plugin used to process mobile payments on WordPress e-commerce sites, contains a security flaw in its access control. This vulnerability allows logged-in customers to potentially perform actions they should not be authorized to do. While the impact is considered medium, it could lead to unauthorized changes in payment processing or order management.
Technical details
A broken access control vulnerability (CWE-862: Missing Authorization) exists in the UPI QR Code Payment Gateway for WooCommerce plugin for WordPress. The flaw allows an authenticated user with 'Customer' level privileges to execute functions that lack proper authorization checks. This could result in unauthorized modifications or actions within the payment gateway component. The issue is resolved in version 1.6.3.
Affected products
- Knit Pay UPI QR Code Payment Gateway for WooCommerce <= 1.6.2
Timeline
- 2026-05-04: disclosed: Reported by ParkHyunWoo
- 2026-06-19: advisory: Patchstack advisory published
- 2026-06-25: other: NVD published date