CVE-2026-1305 - Japanized for WooCommerce <= 2.8.4 - missing authorization to unauthenticated pai...

CVE-2026-1305 - Japanized for WooCommerce <= 2.8.4 - missing authorization to unauthenticated pai...

CVE ID : CVE-2026-1305 Published : Feb. 27, 2026, 9:23 a.m. | 59 minutes ago Description : The Japanized for WooCommerce plugin for WordPress is vulnerable to Improper Authentication in versions up to, and including, 2.8.4. This is due to a flawed permission check in the `paidy_webhook_permission_check` function that unconditionally returns `true` when the webhook signature header is omitted. This makes it possible for unauthenticated attackers to bypass payment verification and fraudulently mark orders as

CVE Details

Published
Feb. 27, 2026
Affected Product: WordPress