5.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Description
The Link Invoice Payment for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the createPartialPayment and cancelPartialPayment functions in all versions up to, and including, 2.8.0. This makes it possible for unauthenticated attackers to create partial payments on any order or cancel any existing partial payment via ID enumeration.
Basic Information
ID
CVE-2025-14971
Source
Wordfence
Published
Jan 27, 2026 at 06:44
Affected Product
Vendor
linknacional
Product
Link Invoice Payment for WooCommerce
Version
*
Affected Versions
linknacional Link Invoice Payment for WooCommerce *
CWE Classification
References
- www.wordfence.com /threat-intel/vulnerabilities/id/96a8fc8b-6f0a-486c-89d1-7211b4ca31bd
- plugins.trac.wordpress.org /browser/invoice-payment-for-woocommerce/tags/2.8.0/Includes/WcPaymentInvoiceEndpoint.php
- plugins.trac.wordpress.org /browser/invoice-payment-for-woocommerce/tags/2.8.0/Includes/WcPaymentInvoiceEndpoint.php