CVE-2026-16947: Manipulable WooCommerce Payment Status

This text was generated using artificial intelligence (AI).On August 29, 2026, CVE-2026-16947 for the WordPress plugin Total Card Payments Processed for WooCommerce Published. Affected versions include those up to and including 7.3.

The vulnerability affects the server-side verification of payment transactions. The plugin does not validate a path provided by the user before generating a server-side verification request. Furthermore, it does not verify the authenticity of the received response.

Are my systems affected? Check now →