CVE-2026-16962

Tamara Checkout <= 1.9.9.20 - Unauthenticated Order Status Manipulation

The Tamara Checkout WordPress plugin through 1.9.9.20 does not verify the order key, a nonce, or any capability on its public payment cancel/fail return URLs, changing a WooCommerce order's status based solely on an attacker-supplied numeric order id, so an unauthenticated attacker can cancel or fail arbitrary orders store-wide by enumerating ids (triggering downstream stock-release and notification side-effects).


We have discovered 213 live websites that are affected by CVE-2026-16962.

Run a Free Instant Scan




Affected Software

Product  Tamara Checkout
Category Wordpress Plugins
Vulnerable Domains213 live websites (100% of Tamara Checkout install base)
Vulnerable Versions
  • from 0 through 1.9.9.20
Vulnerable Versions Count7 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Aug 21, 2026
  • Updated - Aug 21, 2026

Credits

  • Ezekiel Victor (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-16962
United States75 websites



Saudi Arabia55 websites
United Arab Emirates50 websites
Cyprus17 websites
Germany8 websites
GB5 websites
Bulgaria1 websites
France1 websites
Hong Kong1 websites

Website Distribution by TLD

Number of websites using CVE-2026-16962
.com141 websites
.net4 websites
.co3 websites
.org2 websites
.cn1 websites
.co.uk1 websites
.es1 websites
.info1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-16962

Top websites that are affected by CVE-2026-16962. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
************.ae United Arab Emirates***,***
*****.com Cyprus*,***,***
*********.ae United Arab Emirates*,***,***
*******.com United Arab Emirates*,***,***
******************.es United States*,***,***
**********.com United States*,***,***
************.club United States*,***,***
*********************.com United States*,***,***
*******.com United States*,***,***
*****.com Cyprus*,***,***
See full domain list

FAQ

CVE-2026-16962 is Missing Authorization in Tamara Checkout
A total of 213 websites have been identified as vulnerable to CVE-2026-16962, based on global website indexing conducted by WebTechSurvey.
The Tamara Checkout is affected by the CVE-2026-16962 vulnerability.
Tamara Checkout versions up to and including 1.9.9.20 are vulnerable to CVE-2026-16962.