Authorization Bypass Vulnerability in WP Hosting AS Pay with Vipps for WooCommerce
CVE-2026-97259

5.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
30 September 2026

What is CVE-2026-97259?

An authorization bypass vulnerability exists in the Pay with Vipps for WooCommerce plugin, allowing attackers to exploit improperly configured access controls. This issue can lead to unauthorized actions, risking sensitive information exposure or unintended transaction manipulations. Affected users are urged to check their plugin version and review security settings to mitigate risks associated with this vulnerability.

Affected Version(s)

Pay with Vipps for WooCommerce <= 6.2.4

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ananda Dhakal | Patchstack
.