---
id: CVE-2026-78361
title: >-
  The zipMoney(Zip Co) Payments Plugin for WooCommerce WordPress plugin before
  2.4.0 does not perform any authorisation checks on one of its front-end
  request handlers, and does not restrict which option name a caller may supply,
  allowing …
summary: >-
  The zipMoney(Zip Co) Payments Plugin for WooCommerce WordPress plugin before
  2.4.0 does not perform any authorisation checks on one of its front-end
  request handlers, and does not restrict which option name a caller may supply,
  allowing …
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'
cwe:
  - CWE-862
product: zipMoney(Zip Co) Payments Plugin for WooCommerce
affected:
  - zipmoney_zip_co_payments_plugin_for_woocommerce < 2.4.0
published: '2026-09-10'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T15:13:07.090'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-78361'
references:
  - url: 'https://wpscan.com/vulnerability/8b9a00f5-d7f5-447d-b109-d15e2cde3885/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-10T13:09:05.946107Z'
ingestedAt: '2026-09-10T06:34:51.925Z'
epss: 0.00451
epssPercentile: 0.36579
---

## Overview

The zipMoney(Zip Co) Payments Plugin for WooCommerce WordPress plugin before 2.4.0 does not perform any authorisation checks on one of its front-end request handlers, and does not restrict which option name a caller may supply, allowing unauthenticated users to delete arbitrary WordPress options. This can be used to destroy site and access control configuration, deactivate every installed zipMoney(Zip Co) Payments Plugin for WooCommerce WordPress plugin before 2.4.0, and take the site offline.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
