CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-81649: Fundiin cho WooCommerce 0 through 3.4.0

CVE-2026-81649. CVSS 3.1 base score 9.1 (CRITICAL, Source advisory).

Affected technology

Fundiin cho WooCommerce · 0 through 3.4.0
Vendor not specified by the source

Description’s affected range: through 3.4.0 does not have proper authorisation on several of its REST API routes

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

Unauthenticated attackers can disclose the store's payment credentials and customer order data, overwrite the payment gateway configuration so that payments are credited elsewhere, and mark unpaid orders as paid. Source advisory’s CVSS 3.1 assessment (base score 9.1/10) rates confidentiality and integrity impact as high; availability impact as none.

Published

CWE
CWE-863
CCR priority
36.4 /100 (P4)
CVSS 3.1
9.1 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N · Source advisory
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-81649.html