Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total1
Critical0
High0
Medium0
Reset
Showing 1-1 of 1 records
Threat Entry Updated 2026-08-01

CVE-2026-13329 - Buckaroo Woocommerce Payments Plugin

The Buckaroo Woocommerce Payments Plugin WordPress plugin before 4.9.0 does not perform any capability check or nonce validation on an AJAX action that processes payment capture refunds, allowing any authenticated user, including Subscribers, to trigger refunds against captured orders.

PLUGIN Buckaroo Woocommerce Payments

CVE-2026-13329

UNKNOWN CVSS 0.0 2026-08-01
Scroll to top