CVE-2026-84169 UNKNOWN

CVE-2026-84169

Published: 2026-10-05

Description

The UPI QR Code Payment Gateway WordPress plugin through 1.4.3 does not verify that a payment-confirmation request actually belongs to the order and customer it claims to confirm, allowing unauthenticated attackers to mark an arbitrary order as paid without making any payment.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…