{"id":"CVE-2026-84091","published":"2026-09-23T13:17:30.623","lastModified":"2026-09-24T14:42:02.707","description":"The SUMIT Payment Gateway for WooCommerce WordPress plugin before 4.0.0 does not verify with the payment provider that a payment notification is genuine before marking the corresponding order as paid, allowing unauthenticated users to mark a pending order paid without completing payment.","cvssScore":5.3,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","cwes":["CWE-287"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/10c7a9bd-eac0-49eb-9238-d7c477312166/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}