
CVE-2025-14461 The Xendit Payment plugin for WordPress is vulnerable to unauthorized order status manipulation in all versions up to, and including, 6.0.2. This is due to the plugin… https://www.cve.org/CVERecord?id=CVE-2025-14461
Post summary
The CVE-2025-14461 discloses that the Xendit Payment plugin for WordPress allows unauthorized order status manipulation in all versions up to 6.0.2, with no PoC, exploit, or patch information provided.
