The Paymob for WooCommerce WordPress plugin before 4.1.14 does not verify the request signature on one branch of its payment webhook, allowing unauthenticated attackers to mark arbitrary WooCommerce orders as paid without any payment.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 23 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Paymob for WooCommerce WordPress plugin before 4.1.14 does not verify the request signature on one branch of its payment webhook, allowing unauthenticated attackers to mark arbitrary WooCommerce orders as paid without any payment. | |
| Title | Paymob for WooCommerce < 4.1.14 - Unauthenticated Payment Bypass via Unverified Subscription Transaction Callback | |
| Weaknesses | CWE-345 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-23T10:48:46.367Z
Reserved: 2026-09-09T18:30:02.460Z
Link: CVE-2026-87978
Updated: 2026-09-23T10:33:21.971Z
Status : Received
Published: 2026-09-23T11:17:15.880
Modified: 2026-09-23T11:17:15.880
Link: CVE-2026-87978
No data.
OpenCVE Enrichment
No data.
Weaknesses