The ePayco Payment Gateway for WooCommerce WordPress plugin before 8.4.7 does not properly verify the authenticity of payment confirmation requests, allowing unauthenticated attackers to mark orders as paid without a valid gateway signature.
https://wpscan.com/vulnerability/96599654-1d7f-4ff0-a4b4-26e540375a67/