External risk intelligence

Fundiin cho WooCommerce Authorization Bypass and Stored XSS

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-81649

The vulnerability affects a WordPress e-commerce plugin that exposes REST API routes for payment gateway configuration and order processing. As these features are designed to be internet-facing to facilitate public transactions and checkout processes in standard website deployments, the vulnerable surface is public-facing by design.

Cross-site Scripting

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability in a popular WordPress e-commerce plugin could allow unauthorized access to sensitive payment and customer data. Attackers might also be able to redirect payments or fraudulently mark orders as paid, impacting financial operations and customer trust. Additionally, a stored cross-site scripting flaw could expose users to malicious code.

  • Plugin flaw exposes payment and customer data.
  • Critical risk to financial transactions and trust.
  • Confirm relevance and assess exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can target the Fundiin cho WooCommerce WordPress plugin by accessing its exposed REST API routes. This allows them to steal sensitive store payment details and customer order history. They can also redirect payments to their own accounts and falsely mark orders as paid. Additionally, if the store doesn't use the block-based checkout, attackers can inject malicious scripts into a field that is displayed without proper sanitization, leading to stored cross-site scripting attacks.

  • No authentication required to access.
  • Malicious API calls or script injection.
  • Compromised payments and stored XSS.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to access sensitive store payment credentials and customer order information. It may also permit an attacker to redirect payments to their own accounts and falsely mark orders as paid, when supported by the advisory's description of specific REST API routes.

  • Store payment credentials and order data.
  • Unauthenticated access to API routes.
  • Financial loss and data breach.

Operational Fix

Recommended remediation, mitigation, and detection steps

Attackers can exploit this vulnerability in the Fundiin cho WooCommerce WordPress plugin to steal payment credentials, reroute payments, and inject malicious scripts. Responsibility likely falls to application owners, platform teams managing WordPress instances, and security teams for exposure assessment. The first practical step is to identify all affected WooCommerce sites, confirm exposure via the REST API, and then prioritize remediation based on the business criticality of each site.

  • Application owners should take primary responsibility.
  • Verify plugin accessibility and API endpoint exposure.
  • Plan updates during the next maintenance window.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Fundiin cho WooCommerce plugin?

It is a WordPress extension designed to integrate the Fundiin payment gateway into WooCommerce stores. It enables e-commerce sites to offer flexible payment options to customers by managing gateway configurations and processing transaction data directly through the website's backend infrastructure.

What does CWE-863 mean for CVE-2026-81649?

CWE-863 refers to 'Incorrect Authorization.' In this context, it means the plugin fails to properly verify if a user has permission to perform sensitive actions. Because the plugin relies on a static, universal credential for its REST API rather than per-user authentication, attackers can bypass security checks to access private data or alter configuration settings.

Does this vulnerability trigger on all WooCommerce checkout types?

No. While the API-based risks affect the plugin generally, the stored cross-site scripting (XSS) component specifically requires the store to use the 'classic' checkout interface. Sites that exclusively use the newer block-based checkout do not output the unescaped malicious script field and are therefore not susceptible to that specific XSS trigger path.

How does Halo Surface Signal categorize this threat?

Halo Surface Signal identifies this as 'Very likely' to be targeted because the vulnerable REST API routes are intentionally exposed to the internet. Since these components are required to facilitate public-facing transactions and order processing, they are accessible to anyone on the web, making the potential for unauthorized interaction high.

What should I do if I use this plugin?

Begin by auditing your WordPress environment to identify if you have this specific plugin installed. Since the vulnerability allows for unauthorized payment and order manipulation, prioritize checking your payment gateway settings for unauthorized changes and monitor store logs for suspicious API activity while you prepare to update the software.

References