CVE-2026-14830: Unknown Flxwoo

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout session was actually paid before marking the associated order as paid, allowing unauthenticated attackers to complete WooCommerce orders without paying.

Affected products

  • Unknown Flxwoo: before 3.1.1 (fixed in 3.1.1)

Published 2026-07-31. Last modified 2026-08-26.