{"id":"CVE-2026-16739","title":"The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.4 does not verify that a payment-confirmation request originates from the owner of the targeted order, nor that any payment actually occurred, allowing unauthenticated att…","summary":"The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.4 does not verify that a payment-confirmation request originates from the owner of the targeted order, nor that any payment actually occurred, allowing unauthenticated att…","severity":"medium","cvss":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","cwe":["CWE-287"],"published":"2026-08-14","updated":"2026-08-31","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-16739","references":[{"url":"https://wpscan.com/vulnerability/b66b86f9-e49e-4654-84a1-0f2e5c859289/","label":"contact@wpscan.com"}],"tags":["nvd"],"epss":0.00221,"epssPercentile":0.12866,"ingestedAt":"2026-08-31T10:06:34.792Z","slug":"CVE-2026-16739","body":"## Overview\n\nThe Epeken All Kurir for Woocommerce WordPress plugin through 2.1.4 does not verify that a payment-confirmation request originates from the owner of the targeted order, nor that any payment actually occurred, allowing unauthenticated attackers to mark arbitrary orders as confirmed and, in a non-default configuration, paid.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":32,"depthScoreParts":{"impact":32.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}