CVE-2026-104118
UNKNOWN
NVD
CVSS Score
0
Severity
UNKNOWN
Published
Oct 04, 2026
Vendor
unknown
Description
The Razorpay for WooCommerce WordPress plugin before 4.8.8 does not perform ownership or authorization checks on a REST API route used during checkout, allowing unauthenticated attackers to modify the shipping information stored on arbitrary orders.