---
id: CVE-2026-104118
title: >-
  The Razorpay for WooCommerce WordPress plugin before 4.8.8 does not perform
  ownership or authorization checks on a REST API route used during checkout,
  allowing unauthenticated attackers to modify the shipping information stored
  on arbit…
summary: >-
  The Razorpay for WooCommerce WordPress plugin before 4.8.8 does not perform
  ownership or authorization checks on a REST API route used during checkout,
  allowing unauthenticated attackers to modify the shipping information stored
  on arbit…
severity: none
cwe:
  - CWE-639
product: Razorpay for WooCommerce
affected:
  - razorpay_for_woocommerce < 4.8.8
published: '2026-10-04'
updated: '2026-10-04'
sourceUpdated: '2026-10-04T07:16:31.933'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104118'
references:
  - url: 'https://wpscan.com/vulnerability/d94ebc87-c404-4b30-8291-26c4bc2eb63b/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-04T06:55:02.311Z'
---

## Overview

The Razorpay for WooCommerce WordPress plugin before 4.8.8 does not perform ownership or authorization checks on a REST API route used during checkout, allowing unauthenticated attackers to modify the shipping information stored on arbitrary orders.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
