CVE 5.3 MEDIUM

Rupantorpay <= 2.0.0 - Missing Authorization to Unauthenticated Order Status Modification_CVE-2025-15511

5.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Description

The Rupantorpay plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the handle_webhook() function in all versions up to, and including, 2.0.0. This makes it possible for unauthenticated attackers to modify WooCommerce order statuses by sending crafted requests to the WooCommerce API endpoint.

Basic Information

ID CVE-2025-15511
Source Wordfence
Published Jan 28, 2026 at 11:23

Affected Product

Vendor rupantorpay
Product Rupantorpay
Version *
Affected Versions rupantorpay Rupantorpay *

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.