Description
The Conekta Payment Gateway WordPress plugin before 6.2.2 does not verify the authenticity of incoming payment gateway webhook notifications, nor bind the confirmed payment to the targeted order or verify its amount, allowing unauthenticated attackers to mark arbitrary orders as paid without payment.
Published: 2026-08-22
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WordPress "Conekta Payment Gateway" plugin versions prior to 6.2.2 fail to verify the authenticity of payment gateway webhook notifications, do not bind the confirmed payment to the specific order, and do not check the amount. As a result, attackers who can send a forged webhook request can mark any order as paid without a real transaction. This flaw allows unauthenticated users to trigger payment completion for arbitrary orders, potentially causing direct financial loss and undermining order integrity.

Affected Systems

All WordPress sites running the "Conekta Payment Gateway" plugin at a version earlier than 6.2.2 are vulnerable. The flaw exists in the plugin’s webhook handling logic and affects every instance of the plugin on any website that has not applied the update.

Risk and Exploitability

The CVE’s EPSS score is not publicly available and it is not listed in the CISA KEV catalog, but the lack of authentication and input validation in the webhook endpoint renders the vulnerability highly exploitable by anyone who can reach the WordPress site over the network. The attack requires simply sending a crafted HTTP POST to the plugin’s webhook URL; no special privileges, credentials, or host discovery are needed. Because the flaw permits payment status manipulation without payment, the potential impact includes unauthorized fund disbursement and loss of revenue. Without an official fix or workaround, the risk of exploitation remains high for affected installations.

Generated by OpenCVE AI on August 22, 2026 at 07:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the "Conekta Payment Gateway" plugin to version 6.2.2 or later.
  • Restrict the webhook endpoint to known payment gateway IP addresses or require a shared secret key for validation.
  • Regularly audit orders for unexpected paid status changes to detect anomalous activity.

Generated by OpenCVE AI on August 22, 2026 at 07:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 22 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Sat, 22 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Conekta Payment Gateway WordPress plugin before 6.2.2 does not verify the authenticity of incoming payment gateway webhook notifications, nor bind the confirmed payment to the targeted order or verify its amount, allowing unauthenticated attackers to mark arbitrary orders as paid without payment.
Title Conekta Payment Gateway < 6.2.2 - Unauthenticated Order Payment Completion via Webhook Forgery
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-22T06:00:16.315Z

Reserved: 2026-07-23T08:16:28.988Z

Link: CVE-2026-16738

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-22T06:16:15.383

Modified: 2026-08-22T06:16:15.383

Link: CVE-2026-16738

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T08:00:13Z

Weaknesses