Authentication Bypass in Fundiin for WooCommerce Plugin by WordPress
CVE-2026-81649

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
11 October 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-81649?

The Fundiin for WooCommerce WordPress plugin up to version 3.4.0 suffers from inadequate authorization measures. This oversight allows unauthorized attackers to exploit multiple REST API routes, which can lead to significant security breaches. Attackers can potentially expose sensitive payment credentials and customer order information. Furthermore, the vulnerability enables unauthorized users to alter payment gateway configurations to redirect payments, as well as manipulate orders by marking unpaid ones as paid. Additionally, the weak authorization checks permit the unauthorized storage of arbitrary scripts in certain fields, leading to stored Cross-Site Scripting (XSS) vulnerabilities, especially on versions that do not implement block-based checkout.

Affected Version(s)

Fundiin cho WooCommerce 0 <= 3.4.0

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

WPScan
.