Medium 5.3 Unfixed
2026-04-08≤ 4.8.3
CVE-2026-39656
Minimum safe version
4.7.9
Update to 4.7.9 or later to address 7 fixable vulnerabilities
CVE-2026-39656
CVE-2025-14294
Razorpay for WooCommerce < 4.5.7 - Transfers Manipulation via CSRF
Razorpay for WooCommerce < 4.5.7 - Subscriber+ Transfers Manipulation
WordPress Razorpay for WooCommerce Plugin <= 4.5.6 is vulnerable to Broken Access Control
WordPress Razorpay for WooCommerce Plugin <= 4.5.6 is vulnerable to Cross Site Request Forgery (CSRF)
Razorpay for WooCommerce <= 4.5.6 - Cross-Site Request Forgery
Razorpay for WooCommerce <= 4.5.6 - Missing Authorization