CVE-2026-104118: Unknown Razorpay For Woocommerce

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

The Razorpay for WooCommerce WordPress plugin before 4.8.8 does not perform ownership or authorization checks on a REST API route used during checkout, allowing unauthenticated attackers to modify the shipping information stored on arbitrary orders.

Affected products

  • Unknown Razorpay For Woocommerce: before 4.8.8 (fixed in 4.8.8)

Published 2026-10-04. Last modified 2026-10-06.