Sceawere
Vulnerability Detail
CVE-2026-81649UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Fundiin Unauthorized REST API Access
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.1
- Creation Date
- 8h ago
- Vendor
- Unknown
- Product
- Fundiin cho WooCommerce
- Attack Type
- CWE-863 Incorrect Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Fundiin cho WooCommerce WordPress plugin through 3.4.0 does not have proper authorisation on several of its REST API routes, relying instead on a credential that is identical on every installation, allowing unauthenticated attackers to disclose the store's payment credentials and customer order data, overwrite the payment gateway configuration so that payments are credited elsewhere, and mark unpaid orders as paid. The same missing authorisation also allows arbitrary script to be stored in a field which is output unescaped on the classic checkout, leading to unauthenticated stored XSS on stores that do not use the block-based checkout.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.1",
"pubDate": "2026-10-11T07:17:24.703Z",
"pubdate": "2026-10-11T07:17:24.703Z",
"executiveSummary": "The Fundiin for WooCommerce plugin, in versions up to 3.4.0, contains critical security vulnerabilities stemming from improper authorization enforcement within its REST API endpoints.\nThe plugin relies on a static, universal credential for API authentication rather than unique site-specific keys, effectively bypassing standard WordPress authentication protocols.\nThis flaw allows unauthenticated attackers to perform unauthorized actions, including the extraction of sensitive payment gateway credentials and private customer order data.\nFurthermore, the vulnerability permits the manipulation of payment configuration settings—enabling traffic redirection to attacker-controlled accounts—and the fraudulent modification of order statuses from unpaid to paid.\nAdditionally, the lack of input sanitization in certain fields leads to stored Cross-Site Scripting (XSS) risks on classic checkout pages.\nThese vulnerabilities pose a severe risk to store integrity, data confidentiality, and financial security, as attackers do not require valid administrative or customer privileges to execute these actions.\nGiven that the authentication mechanism is identical across all installations, this vulnerability is globally exploitable.",
"technicalDetails": "The root cause of these vulnerabilities lies in the insecure implementation of the REST API authorization layer within the Fundiin for WooCommerce plugin. Rather than leveraging the built-in WordPress REST API authentication mechanisms (such as nonces or current_user_can() checks), the plugin utilizes a hardcoded, static credential shared across all installations to validate API requests. This design flaw essentially creates a global backdoor, allowing any remote, unauthenticated attacker to interact with the plugin’s REST API endpoints.\nThe attack flow begins with an attacker identifying the exposed REST API routes implemented by the plugin. By supplying the known static credential, the attacker successfully bypasses security controls and gains unauthorized access to internal plugin functionality. With this access, an attacker can programmatically query endpoints responsible for retrieving payment gateway configurations and sensitive customer order data, leading to a complete compromise of PII (Personally Identifiable Information).\nBeyond data exfiltration, the API allows for unauthorized write operations. By interacting with the payment configuration endpoints, an attacker can overwrite existing API keys, redirecting transaction funds to an arbitrary destination. Furthermore, the ability to modify the status of individual orders allows for the manipulation of fulfillment cycles, potentially resulting in significant financial loss for the merchant.\nThe vulnerability also introduces a persistent threat via stored XSS. The REST API permits the injection of arbitrary scripts into specific data fields. Because these fields are rendered without adequate output escaping on the classic WooCommerce checkout page, the injected payload executes in the context of the victim's browser when they visit the checkout page. This enables the theft of session cookies, credential harvesting, or further redirection of user traffic.\nThe scope of impact includes: 1) Unauthorized disclosure of payment gateway secrets; 2) Exfiltration of customer order databases; 3) Tampering with payment configurations to facilitate financial fraud; 4) Fraudulent order status updates; and 5) Stored XSS attacks leading to client-side compromise. The vulnerability affects all versions up to 3.4.0 and requires no specific authentication or elevated privileges, making it accessible to any actor capable of interacting with the target’s network."
}