Broken Access Control in UPI QR Code Payment Gateway for WooCommerce
CVE-2026-56023

5.4MEDIUM

What is CVE-2026-56023?

The UPI QR Code Payment Gateway for WooCommerce, up to version 1.6.2, exhibits a vulnerability due to insufficient access control mechanisms. This flaw allows unauthorized users to bypass security checks, potentially leading to unauthorized actions on behalf of legitimate users. Such a vulnerability can compromise the integrity of transactions and sensitive user data, making it critical for users to update to the latest version to secure their eCommerce platforms.

Affected Version(s)

UPI QR Code Payment Gateway for WooCommerce <= 1.6.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ParkHyunWoo | Patchstack Bug Bounty Program
.