Rupantorpay WordPress Plugin Missing Authorization Vulnerability in Webhook Handling

Vulnerability

A vulnerability exists in the Rupantorpay plugin for WordPress, specifically in versions through 2.0.0. The issue arises from a lack of capability checks in the handle_webhook() function, allowing unauthenticated attackers to alter WooCommerce order statuses. This is achieved by sending crafted requests to the WooCommerce API endpoint, exploiting the missing authorization to unauthorizedly modify order data.

Impact

Exploitation of this vulnerability allows for unauthorized changes to WooCommerce order statuses, which could disrupt order management and fulfillment processes.

Added: Jan 28, 2026, 12:34 PM
Updated: Jan 28, 2026, 12:34 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.7
remediation
0.0
relevance
2.4
threat
3.2
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.