Description
The PAYGENT for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.6. This is due to missing authorization checks on the paygent_check_webhook function combined with the paygent_permission_callback function unconditionally returning true on line 199. This makes it possible for unauthenticated attackers to manipulate payment callbacks and modify order statuses by sending forged payment notifications via the `/wp-json/paygent/v1/check/` endpoint.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Tue, 20 Jan 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 19 Jan 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Shoheitanaka
Shoheitanaka japanized For Woocommerce Wordpress Wordpress wordpress |
|
| Vendors & Products |
Shoheitanaka
Shoheitanaka japanized For Woocommerce Wordpress Wordpress wordpress |
Sat, 17 Jan 2026 08:30:00 +0000
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-01-20T19:23:14.231Z
Reserved: 2025-12-04T22:46:03.449Z
Link: CVE-2025-14078
Updated: 2026-01-20T19:18:21.136Z
Status : Awaiting Analysis
Published: 2026-01-17T09:15:51.390
Modified: 2026-01-26T15:05:39.840
Link: CVE-2025-14078
No data.
OpenCVE Enrichment
Updated: 2026-01-19T09:19:25Z
Weaknesses