Epeken for WooCommerce: Orders Can Be Marked Paid Without Authorization

Step by step
How the attack unfolded
Click a phase for details – or let the animation play through.
PHASE 1/5 · Reconnaissance

The attacker identifies WooCommerce shops running the vulnerable plugin.

T1595 – Active Scanning T1592 – Gather Victim Host Information
  • Target: WooCommerce shops using Epeken All Kurir for WooCommerce
  • Affected: all versions up to and including 2.1.2
  • At least 400 active installations worldwide
PHASE 2/5 · Initial Access

Without authentication, the attacker sends crafted requests to the public-facing shop.

T1190 – Exploit Public-Facing Application
  • CVE-2026-16739, CVSS 5.9 (medium)
  • No user account or password required
  • Unauthenticated attackers send requests directly to the shop
PHASE 3/5 · Execution / Defense Evasion

The missing authorization and plausibility check is abused to bypass the payment verification.

T1211 – Exploitation for Defense Evasion
  • Vulnerability in the plugin's payment confirmation flow
  • Missing authorization check: server blindly trusts the request
  • The payment provider's verification step is bypassed
PHASE 4/5 · Manipulation

Arbitrary orders are marked as confirmed or, under non-default config, as paid.

T1565.001 – Data Manipulation: Stored Data Manipulation
  • Default config: orders can be marked as confirmed
  • Non-default config: orders can be marked as paid
  • Status change without payment received and without authorization
PHASE 5/5 · Impact

Goods may be shipped although no payment was ever received, causing financial loss.

T1657 – Financial Theft
  • Orders falsely marked as paid may trigger shipment of goods
  • Direct financial loss for small and mid-sized online shops
  • No fix mentioned in the advisory – disabling the plugin is recommended
More security news
You might also be interested in
Critical Elementor Pro Flaw: Attackers Can Fully Take Over WordPress Sites
A file upload bug in Elementor Pro up to 4.2.1 allows RCE without login. Version 4.2.2 fixes the flaw – update now!
Pods Plugin: Critical Flaw Enables Admin Takeover, No Login
A critical flaw in the WordPress plugin Pods lets attackers overwrite admin passwords without login. Over 100,000 sites are affected.
miniOrange SAML SSO: Critical Bypass Turns Attackers Into Admins
Two critical auth bypasses in the miniOrange SAML SSO plugin allow forged SAML assertions—up to full WordPress admin access.