CVE Database /
CVE-2026-56048
CVE · Medium
CVE-2026-56048 — Payment Gateway Based Fees and Discounts for WooCommerce [checkout-fees-for-woocommerce] < 3.1.0
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-56048
|
Payment Gateway Based Fees and Discounts for WooCommerce [checkout-fees-for-woocommerce] < 3.1.0 |
Authorization Bypass Through User-Controlled Key |
Medium
6.5
|
< 3.1.0
|
3.1.0 |
2026-06-25 |
—
|
CVE-2026-56048
The Payment Gateway Based Fees and Discounts for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.0.0 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to perform an unauthorized action.
Source:
Wordfence
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings