---
id: CVE-2026-104651
title: >-
  The Yaad Sarig Payment Gateway For WC WordPress plugin before 2.2.13 does not
  verify authorization or that the requesting user owns the target order in
  several of its order payment-processing actions, allowing any authenticated
  user, inc…
summary: >-
  The Yaad Sarig Payment Gateway For WC WordPress plugin before 2.2.13 does not
  verify authorization or that the requesting user owns the target order in
  several of its order payment-processing actions, allowing any authenticated
  user, inc…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-639
product: Yaad Sarig Payment Gateway For WC
affected:
  - yaad_sarig_payment_gateway_for_wc < 2.2.13
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T14:52:43.420'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104651'
references:
  - url: 'https://wpscan.com/vulnerability/be0e4e18-0bd7-455a-93f6-8f4a7f18b7e1/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-07T09:58:47.078380Z'
ingestedAt: '2026-10-07T08:20:03.938Z'
epss: 0.00132
epssPercentile: 0.02371
---

## Overview

The Yaad Sarig Payment Gateway For WC WordPress plugin before 2.2.13 does not verify authorization or that the requesting user owns the target order in several of its order payment-processing actions, allowing any authenticated user, including subscribers, to act on and alter orders belonging to other customers.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
