← לוח פגיעויות

CVE-2026-7862

גבוהה 8.6

תיאור (מקור, אנגלית)

The Eupago Gateway For Woocommerce WordPress plugin before 4.7.2 does not properly restrict access to its refund request handler, allowing unauthenticated attackers to initiate refunds against any WooCommerce order using the merchant's payment gateway credentials, and for applicable payment methods, to redirect refunded funds to an attacker-controlled bank account.

מדדים

CVSS 3.1
8.6 (HIGH) מקור הציון: CNA CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
EPSS — סבירות ניצול
0% (אחוזון 000) נכון ל-6/8/2026
CWE
CWE-284

קישורים