CRITICAL 9.1 CVE-2026-78361 Published 10 Sept 2026

WooCommerce zipMoney Plugin Unauthenticated Option Deletion

Worried this affects one of your servers?

The zipMoney Payments Plugin for WooCommerce WordPress plugin before 2.4.0 has a critical security vulnerability.

WooCommerce plugin users are at risk as the plugin does not perform authorisation checks on one of its front-end request handlers, allowing unauthenticated users to delete arbitrary WordPress options.

This can lead to the destruction of site and access control configuration, deactivation of the plugin, and potentially take the site offline.

Reference: CVE-2026-78361 on NVD

← Back to Security News