CRITICAL 9.1 CVE-2026-81649 Published 11 Oct 2026

Fundiin cho WooCommerce Plugin Missing Auth and Stored XSS Vulnerabilities

Worried this affects your website?

The Fundiin cho WooCommerce plugin through 3.4.0 is affected by a missing authorisation vulnerability on several REST API routes. The plugin relies on a credential that is identical on every installation, allowing unauthenticated attackers to access the routes.

Attackers can disclose the store's payment credentials and customer order data, overwrite the payment gateway configuration so payments are credited elsewhere, and mark unpaid orders as paid.

The same missing authorisation also allows arbitrary script to be stored in a field that is output unescaped on the classic checkout, leading to unauthenticated stored XSS on stores that do not use the block-based checkout.

  • Affected versions: through 3.4.0
  • Impact: payment credential and order data disclosure, payment gateway reconfiguration, order status manipulation, stored XSS
  • Condition: stores not using block-based checkout are exposed to stored XSS

Reference: CVE-2026-81649 on NVD

← Back to Security News