CVE-2026-12972: Unknown Payplus Payment Gateway
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to tamper with the payment-related metadata of arbitrary WooCommerce orders.
Affected products
- Unknown Payplus Payment Gateway: before 8.2.2 (fixed in 8.2.2)
Published 2026-07-20. Last modified 2026-07-21.