---
id: CVE-2026-13329
title: >-
  The Buckaroo Woocommerce Payments Plugin WordPress plugin before 4.9.0 does
  not perform any capability check or nonce validation on an AJAX action that
  processes payment capture refunds, allowing any authenticated user, including
  Subscri…
summary: >-
  The Buckaroo Woocommerce Payments Plugin WordPress plugin before 4.9.0 does
  not perform any capability check or nonce validation on an AJAX action that
  processes payment capture refunds, allowing any authenticated user, including
  Subscri…
severity: none
published: '2026-08-01'
updated: '2026-08-01'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-13329'
references:
  - url: 'https://wpscan.com/vulnerability/6e60d271-574d-4259-ab51-32a014e480d4/'
    label: contact@wpscan.com
tags:
  - nvd
epss: 0.00299
epssPercentile: 0.201
ingestedAt: '2026-08-02T01:16:32.384Z'
---

## Overview

The Buckaroo Woocommerce Payments Plugin WordPress plugin before 4.9.0 does not perform any capability check or nonce validation on an AJAX action that processes payment capture refunds, allowing any authenticated user, including Subscribers, to trigger refunds against captured orders.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
