« Back to list

UPI QR Code Payment Gateway

UPI QR Code Payment Gateway: vulnerabilities and CVEs

UPI QR Code Payment Gateway has 2 published vulnerabilities, 2 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs2
Last 12 months2
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-84169Medium (5.3)0.18%—Oct 5, 2026
The UPI QR Code Payment Gateway WordPress plugin through 1.4.3 does not verify that a payment-confirmation request actually belongs to the order and customer it claims to confirm, allowing unauthenticated attackers to…
CVE-2026-56023Medium (5.4)0.29%—Jun 25, 2026
Customer Broken Access Control in UPI QR Code Payment Gateway for WooCommerce <= 1.6.2 versions.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1190 Exploit Public-Facing Application1
  2. T1565.003 Runtime Data Manipulation1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.