Sceawere

Vulnerability Detail

CVE-2026-16739UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Epeken All Kurir Order Status Bypass

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.9
Creation Date
12h ago
Vendor
Unknown
Product
Epeken All Kurir for Woocommerce
Attack Type
CWE-287 Improper Authentication
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Attack Complexity
HIGH

Narrative and Response

Description

The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.2 does not verify that a payment-confirmation request originates from the owner of the targeted order, nor that any payment actually occurred, allowing unauthenticated attackers to mark arbitrary orders as confirmed and, in a non-default configuration, paid.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.9",
  "pubDate": "2026-08-14T06:17:03.153Z",
  "pubdate": "2026-08-14T06:17:03.153Z",
  "executiveSummary": "An improper authorization and missing payment verification vulnerability exists in the Epeken All Kurir for Woocommerce WordPress plugin through 2.1.2.\nThe flaw allows unauthenticated remote attackers to arbitrarily manipulate order states by sending forged payment-confirmation requests.\nSpecifically, threat actors can mark targeted orders as confirmed and, depending on the configuration, falsely mark them as paid without requiring any prior authentication, ownership verification, or actual financial transaction.\nThe primary impact of this vulnerability includes financial fraud, unauthorized order fulfillment, inventory depletion, and business logic bypasses within vulnerable WooCommerce installations.\nThe risk implications are critical for e-commerce platforms utilizing the affected plugin, as malicious actors can exploit the missing validation controls entirely over the network with zero privileges.\nExploitation requirements are minimal, as the endpoint responsible for processing payment confirmations lacks proper request origin validation and transactional state verification.",
  "technicalDetails": "The root cause of the vulnerability stems from inadequate access control enforcement and the complete absence of cryptographic or session-based verification mechanisms within the plugin's payment-confirmation handling routine.\nThe vulnerable component is the order processing and payment-confirmation endpoint exposed by the Epeken All Kurir for Woocommerce WordPress plugin in versions through 2.1.2.\nBecause the application fails to validate whether an incoming payment-confirmation request originates from the legitimate owner of the targeted order, and likewise fails to query or confirm that an actual payment transaction occurred via a payment gateway, the system blindly trusts incoming parameters.\nAuthentication and privilege requirements are entirely absent; the vulnerability is exposed to unauthenticated external entities over the network.\nThe step-by-step attack flow proceeds as follows: First, the attacker identifies a target order ID within the compromised WooCommerce instance. Second, the attacker crafts a malicious HTTP request directed at the plugin's payment-confirmation endpoint, supplying the targeted order ID and parameters indicating a successful payment state. Third, the endpoint processes the request without verifying the sender's identity or cross-referencing a valid transaction receipt from a payment gateway. Finally, the backend application updates the order status in the database, marking the arbitrary order as confirmed and potentially paid.\nPost-exploitation impact includes unauthorized execution of downstream fulfillment processes, shipment of physical goods without receiving funds, and severe disruption of merchant accounting and inventory systems."
}
CVE-2026-16739: Epeken All Kurir Order Status Bypass (MEDIUM Severity, CVSS: 5.9) - Sceawere