Executive brief
The Eupago Gateway For Woocommerce plugin, which enables online stores to process payments, contains a security flaw in how it handles refund requests. An unauthorized attacker can exploit this to trigger refunds for any customer order without needing to log in. In some cases, this allows the attacker to divert the refunded money into their own bank account, leading to direct financial loss and operational disruption for the merchant.
Technical details
The vulnerability is classified as an Improper Access Control (CWE-284) within the refund request handler of the Eupago Gateway For Woocommerce plugin. Due to a lack of authorization checks, an unauthenticated remote attacker can send crafted requests to the handler to initiate refunds for arbitrary WooCommerce orders using the merchant's stored payment gateway credentials. For specific payment methods supported by the gateway, the attacker can further manipulate the request to redirect the refunded funds to a bank account under their control. The issue is resolved in version 4.7.2.
Affected products
- Eupago Eupago Gateway For Woocommerce < 4.7.2
Timeline
- 2026-05-07: disclosed: Initial public disclosure by WPScan
- 2026-05-28: advisory: NVD publication date
- 2026-05-28: patched: Fix confirmed in version 4.7.2