Impact
The Paymob for WooCommerce WordPress plugin older than version 4.1.14 fails to validate the request signature on the card-token branch of its payment webhook. This flaw allows an attacker to send crafted webhook requests that create or overwrite card-token records for any user. The attacker can thereby inject fraudulent payment entries and observe the presence of registered user accounts, effectively enumerating users on the site.
Affected Systems
The vulnerability affects any installation of the Paymob for WooCommerce plugin for WordPress deployed before version 4.1.14. Users who have not upgraded to 4.1.14 or newer are exposed.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation under current measurement. The flaw is not listed in the CISA KEV catalog, implying no public exploit has been observed yet. Attackers would need network access to the site's webhook endpoint and could gain unauthorized access to user card data or discover user identities. The lack of signature verification makes the attack relatively straightforward for anyone who can reach the endpoint.
OpenCVE Enrichment