CVE-2019-14978: Woocommerce Payu India Payment Gateway

Medium severity, CVSS 5.3. EPSS: 1.2% chance of exploitation in the next 30 days.

/payu/icpcheckout/ in the WooCommerce PayU India Payment Gateway plugin 2.1.1 for WordPress allows Parameter Tampering in the purchaseQuantity=1 parameter, as demonstrated by purchasing an item for lower than the intended price.

Affected products

  • Woocommerce Payu India Payment Gateway: version 2.1.1 only

Published 2019-08-29. Last modified 2026-06-17.