WP Clinic
Log in Sign up

CVE · Medium

CVE-2026-56048 — Payment Gateway Based Fees and Discounts for WooCommerce [checkout-fees-for-woocommerce] < 3.1.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-56048 Payment Gateway Based Fees and Discounts for WooCommerce [checkout-fees-for-woocommerce] < 3.1.0 Authorization Bypass Through User-Controlled Key Medium 6.5 < 3.1.0 3.1.0 2026-06-25

CVE-2026-56048

The Payment Gateway Based Fees and Discounts for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.0.0 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to perform an unauthorized action.

Source: Wordfence

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.