Published on 15 August 2026
Imagine a stranger could mark an order in your online shop as "paid" – without any money ever changing hands. This is exactly the scenario described by a newly reported security vulnerability in the WooCommerce plugin Epeken All Kurir for WooCommerce. Attackers need neither a user account nor a password. They don't even have to log in to your shop. For operators of small and medium-sized online shops in Germany, that's a reason to take a close look right now.
The vulnerability is tracked under the identifier CVE-2026-16739 – the internationally unique number under which security vulnerabilities are catalogued. It affects all versions of the plugin up to and including 2.1.2 and was published on 14 August 2026 by the security service provider FreshySites in a security bulletin. The severity is rated as medium with a CVSS score of 5.9. CVSS is a standardised scoring system from 0 to 10 that rates the danger posed by a security vulnerability.
The Epeken All Kurir for WooCommerce plugin is used in WooCommerce shops – the popular shop system for WordPress – to connect to a courier or shipping service provider. As part of this integration, the plugin also handles processes surrounding the payment confirmation of orders.
This is precisely where the problem lies. According to the report, the plugin up to and including version 2.1.2 contains a vulnerability in payment confirmation. Unauthenticated attackers – that is, people who are neither logged in nor otherwise authorised – can send requests to the shop that mark arbitrary orders as confirmed. And under a certain non-default configuration, orders can even be marked as paid.
The core of the flaw: the plugin does not adequately check whether a confirmation actually comes from the rightful owner of the order – and whether a payment has actually been made. The system therefore blindly trusts the incoming request instead of checking it against the actual facts. This missing authorisation and plausibility check opens the door to abuse.
You can picture it like a bouncer who waves through anyone claiming to be invited – without checking the guest list. In technical terms, this is called a missing authorisation check. It means that the server accepts an instruction (here: "mark this order as confirmed/paid") and executes it without checking whether the sender even has the right to do so.
In a properly functioning payment process, an order should only be considered paid once the payment service provider – such as a credit card or bank transfer provider – confirms receipt of the money. With this vulnerability, however, this verification step can be bypassed. An attacker can send an appropriately crafted request to the shop, and the plugin then changes the status of the order.
Two levels must be distinguished here:
It is precisely the second level that is economically explosive: if an order is falsely recorded as paid, in the worst case goods could be shipped for which no payment was ever received.
Affected are operators of WooCommerce shops that have installed and activated the plugin Epeken All Kurir for WooCommerce in a version up to and including 2.1.2. According to the report, there are at least 400 active installations of this plugin.
Compared to large plugins, that's a manageable number – but for each individual affected shop, the vulnerability can have concrete financial consequences. If you operate an online shop with WooCommerce and use this courier integration, you should read the following section particularly carefully.
You don't have to be a technical expert to determine whether your shop is vulnerable. Go through these steps:
Make a note of the result. If the plugin is installed and active in an affected version, you should act immediately.
The present report does not name an already available update that fixes the vulnerability. This means you should not rely on an update alone, but first actively limit the risk. Take a pragmatic approach:
Whether the vulnerability is actively being exploited by attackers is, according to the material available, unknown. This is not an all-clear – it merely means that no confirmed attacks have been reported. Particularly with vulnerabilities that require no login and offer a direct economic advantage, caution is advised. Anyone who waits until the first attacks are documented often acts too late.
With a CVSS score of 5.9, the vulnerability lies in the medium range. However, this needs to be put into perspective when you consider the possible practical damage. While the vulnerability does not allow a complete takeover of the server or the exfiltration of large amounts of data, the economic core is immediately tangible: orders could be considered paid without an actual payment being received.
For a small online shop, this can have direct financial consequences – for example, when goods are shipped for which no money has been received. On top of that comes the effort of manually reviewing orders and cleaning up erroneous status changes. The medium severity should therefore not lead to complacency.
The available material does not indicate that personal data – such as customer data – has been or could have been leaked through this vulnerability. The focus is on the unauthorised change of order and payment status, not on data theft.
Nevertheless, the following applies: if, in the course of your review, you find that unauthorised access to your shop has taken place and personal data could be affected, the reporting and documentation obligations of the General Data Protection Regulation apply. In such a case, document your findings carefully and, when in doubt, have it professionally assessed whether a report to the competent supervisory authority is necessary. In general, it is advisable to log security-relevant incidents internally – even when there is initially no reporting obligation.
The vulnerability CVE-2026-16739 in the Epeken All Kurir for WooCommerce plugin shows once again how a single plugin can become a gateway. Attackers need no login to mark orders as confirmed and, under certain settings, even as paid. All versions up to and including 2.1.2 are affected, and at least 400 shops actively use the plugin.
The key steps in brief: check whether the plugin is installed on your site and active in an affected version. Make a backup, install an update as soon as it is available, and consider temporary deactivation if the function is not strictly needed. Check your orders for unusual status changes and reconcile "paid" notifications with the actual payments received.
The severity is medium, but the economic consequence for a small shop can certainly be tangible. Anyone who acts now closes the vulnerability before it turns into real damage. Keep an eye on the vendor's page and your plugin menu so that you can install a provided security update promptly.
Source: Security bulletin from FreshySites dated 14 August 2026 on CVE-2026-16739.