Junglewise Threat Intelligence

CVE-2026-57424: knitpay Razorpay Payment Links for WooCommerce missing authorization

CVE-2026-57424 · Severity: medium · CVSS 6.5 · Published 2026-07-13

Executive brief

A security vulnerability exists in the Razorpay Payment Links plugin for WooCommerce, which is used by online stores to process customer payments. This flaw allows unauthorized individuals to bypass security checks and potentially perform actions they should not be allowed to, such as interfering with payment link configurations. This could lead to disruptions in the checkout process or unauthorized changes to how payments are handled on the site.

Technical details

A Missing Authorization (CWE-862) vulnerability exists in the knitpay Razorpay Payment Links for WooCommerce (rzp-woocommerce) plugin through version 2.1.4. The flaw stems from insufficient access control checks on certain functions, allowing an unauthenticated remote attacker to execute actions that should be restricted to higher-privileged users. According to the CVSS vector, the attack is low complexity and requires no user interaction, potentially impacting the integrity and availability of the payment link system. The issue is addressed in version 2.1.5.

Affected products

  • knitpay Razorpay Payment Links for WooCommerce (rzp-woocommerce) <= 2.1.4

Timeline

  • 2026-06-17: other: Reported by researcher dunvu0
  • 2026-07-08: advisory: Patchstack advisory published
  • 2026-07-13: disclosed: CVE published to NVD
  • 2026-07-13: patched: Version 2.1.5 released to address the vulnerability

References