CVE-2026-84169 PUBLISHED

UPI QR Code Payment Gateway <= 1.4.3 - Unauthenticated Cross-Order Payment-Status Forgery

Assigner: WPScan
Reserved: 01.09.2026 Published: 05.10.2026 Updated: 05.10.2026

The UPI QR Code Payment Gateway WordPress plugin through 1.4.3 does not verify that a payment-confirmation request actually belongs to the order and customer it claims to confirm, allowing unauthenticated attackers to mark an arbitrary order as paid without making any payment.

Product Status

Vendor Unknown
Product UPI QR Code Payment Gateway
Versions Default: unknown
  • affected from 0 to 1.4.3 (incl.)

Credits

  • Pedro Pinho finder
  • WPScan coordinator

References

Problem Types

  • CWE-639 Authorization Bypass Through User-Controlled Key CWE