CVE-2026-11575 is a high-severity payment authorization bypass vulnerability in the PhonePe Payment Solutions WordPress plugin, affecting all versions prior to 3.1.0. The flaw allows unauthenticated remote attackers to forge payment-success callbacks and mark unpaid WooCommerce orders as paid without any actual transaction taking place. The vulnerability carries a CVSS v3.1 score of 7.5 (High) and was remediated in version 3.1.0, released June 25, 2026.
