Junglewise Threat Intelligence

CVE-2026-56048: Tyche Softwares Payment Gateway Based Fees and Discounts for WooCommerce IDOR

CVE-2026-56048 · Severity: medium · CVSS 6.5 · Published 2026-06-26

Vendors: Tyche Softwares.

Executive brief

A vulnerability exists in a WordPress plugin used to manage additional fees or discounts based on the payment method selected at checkout. An unauthenticated attacker can exploit this flaw to bypass authorization checks and potentially modify or interact with data they should not have access to. This could lead to unauthorized changes in transaction details or disruption of the payment process.

Technical details

The Payment Gateway Based Fees and Discounts for WooCommerce plugin for WordPress is vulnerable to an Insecure Direct Object Reference (IDOR) flaw in versions up to and including 3.0.0. The vulnerability stems from insufficient authorization checks when accessing or modifying objects via user-controlled input. An unauthenticated remote attacker can exploit this by sending crafted requests to interact with database objects or sensitive files without proper permission. This can result in unauthorized data modification or integrity loss. The issue is addressed in version 3.1.0.

Affected products

  • Tyche Softwares Payment Gateway Based Fees and Discounts for WooCommerce <= 3.0.0

Timeline

  • 2026-03-24: other: Reported by Jakub Herman
  • 2026-06-25: disclosed: Vulnerability published by Patchstack
  • 2026-06-26: advisory: NVD published date

References