CVE-2026-84043: Unknown Epayco Payment Gateway For Woocommerce
Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.
The ePayco Payment Gateway for WooCommerce WordPress plugin before 8.4.7 does not properly verify the authenticity of payment confirmation requests, allowing unauthenticated attackers to mark orders as paid without a valid gateway signature.
Affected products
- Unknown Epayco Payment Gateway For Woocommerce: before 8.4.7 (fixed in 8.4.7)
Published 2026-09-04. Last modified 2026-09-08.