Input validation vulnerability in Razorpay for WooCommerce 4.5.6

The Razorpay for WooCommerce plugin, which is used to integrate the Razorpay payment gateway with WordPress websites, is not secure in all versions up to and including 4.5.6. This is because it does not have proper validation for certain requests sent from the website’s administrator. This means that someone who is not authorized to make changes to the website can trick an administrator into clicking a link and make changes to the plugin, including reversing payments and creating new ones.

Detected in:

Razorpay for WooCommerce fixed vulnerable versions: >= * <= 4.5.6

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.