Description
The Super Payments WordPress plugin before 1.43.1 does not properly verify the authenticity of incoming payment webhook notifications, as the signing key used to validate their signature is empty by default, allowing unauthenticated attackers to forge a valid signature and mark arbitrary WooCommerce orders as paid without payment.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 09 Oct 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Super Payments WordPress plugin before 1.43.1 does not properly verify the authenticity of incoming payment webhook notifications, as the signing key used to validate their signature is empty by default, allowing unauthenticated attackers to forge a valid signature and mark arbitrary WooCommerce orders as paid without payment. | |
| Title | Super Payments < 1.43.1 - Unauthenticated Payment Confirmation Forgery via Webhook Signature | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-10-09T11:03:34.916Z
Reserved: 2026-09-30T12:37:57.952Z
Link: CVE-2026-103329
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.