Description
The SUMIT Payment Gateway for WooCommerce WordPress plugin before 4.0.0 does not verify with the payment provider that a payment notification is genuine before marking the corresponding order as paid, allowing unauthenticated users to mark a pending order paid without completing payment.
Published: 2026-09-23
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Payment Confirmation
Action: Patch Now
AI Analysis

Impact

The SUMIT Payment Gateway for WooCommerce plugin before version 4.0.0 fails to verify that a payment provider's notification is authentic before marking an order as paid. An attacker can therefore forge a payment notification and cause the system to treat a pending order as paid, granting access to paid content or services without completing payment. This flaw allows attackers to manipulate order status without authorization, exploiting a weakness in access control.

Affected Systems

WordPress sites that have installed the SUMIT Payment Gateway for WooCommerce plugin and are running any version prior to 4.0.0. The vendor is not identified in the public references, but the vulnerability is specific to this plugin used within WooCommerce.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity, and the EPSS score is not available, so the estimated exploitation probability cannot be quantified. The vulnerability is listed as not being in the CISA KEV catalog. Attackers can exploit the flaw remotely by sending a forged IPN request over the network to the plugin’s notification endpoint, with no authentication required. While no public exploitation has been reported, the fact that the issue can be triggered by any unauthenticated user raises concern for sites with active payment gateways.

Generated by OpenCVE AI on September 23, 2026 at 15:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the SUMIT Payment Gateway for WooCommerce plugin to version 4.0.0 or later.
  • If an immediate upgrade is not feasible, temporarily disable or restrict access to the IPN endpoint so only legitimate payment provider traffic can reach it.
  • Implement server‑side verification of payment notifications—such as checking a digital signature or querying the payment provider’s API—to confirm authenticity until the patch is applied.

Generated by OpenCVE AI on September 23, 2026 at 15:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 23 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 23 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description The SUMIT Payment Gateway for WooCommerce WordPress plugin before 4.0.0 does not verify with the payment provider that a payment notification is genuine before marking the corresponding order as paid, allowing unauthenticated users to mark a pending order paid without completing payment.
Title SUMIT Payment Gateway for WooCommerce < 4.0.0 - Unauthenticated Payment Confirmation Forgery via bit IPN
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-23T12:38:20.929Z

Reserved: 2026-09-01T06:34:21.865Z

Link: CVE-2026-84091

cve-icon Vulnrichment

Updated: 2026-09-23T12:36:29.752Z

cve-icon NVD

Status : Received

Published: 2026-09-23T13:17:30.623

Modified: 2026-09-23T13:17:30.623

Link: CVE-2026-84091

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T15:30:07Z

Weaknesses