CVE-2025-15513 - Float Payment Gateway <= 1.1.9 - improper authorization to unauthenticated order

CVE-2025-15513 - Float Payment Gateway <= 1.1.9 - improper authorization to unauthenticated order

CVE ID : CVE-2025-15513 Published : Jan. 14, 2026, 7:16 a.m. | 16 minutes ago Description : The Float Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to improper error handling in the verifyFloatResponse() function in all versions up to, and including, 1.1.9. This makes it possible for unauthenticated attackers to mark any WooCommerce order as failed. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
Jan. 14, 2026
Affected Product: WordPress

Source: Telegram CVE Monitor