Description
The Paymob for WooCommerce WordPress plugin before 4.1.14 does not verify the request signature on the card-token branch of its payment webhook, allowing unauthenticated attackers to write a card-token record to any user's account and to enumerate registered accounts.
Published: 2026-09-23
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Card Data Write and Account Enumeration
Action: Apply Patch
AI Analysis

Impact

The Paymob for WooCommerce WordPress plugin older than version 4.1.14 fails to validate the request signature on the card-token branch of its payment webhook. This flaw allows an attacker to send crafted webhook requests that create or overwrite card-token records for any user. The attacker can thereby inject fraudulent payment entries and observe the presence of registered user accounts, effectively enumerating users on the site.

Affected Systems

The vulnerability affects any installation of the Paymob for WooCommerce plugin for WordPress deployed before version 4.1.14. Users who have not upgraded to 4.1.14 or newer are exposed.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation under current measurement. The flaw is not listed in the CISA KEV catalog, implying no public exploit has been observed yet. Attackers would need network access to the site's webhook endpoint and could gain unauthorized access to user card data or discover user identities. The lack of signature verification makes the attack relatively straightforward for anyone who can reach the endpoint.

Generated by OpenCVE AI on September 23, 2026 at 15:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Paymob for WooCommerce to version 4.1.14 or later, which adds request signature verification for the card-token webhook branch.
  • If upgrading is not immediately possible, temporarily disable the card-token webhook endpoint or restrict access to internal network by firewall to prevent unauthenticated requests.
  • Monitor the plugin logs for unusual webhook activity and review stored card-token records for any unauthorized entries.

Generated by OpenCVE AI on September 23, 2026 at 15:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description The Paymob for WooCommerce WordPress plugin before 4.1.14 does not verify the request signature on the card-token branch of its payment webhook, allowing unauthenticated attackers to write a card-token record to any user's account and to enumerate registered accounts.
Title Paymob for WooCommerce < 4.1.14 - Unauthenticated Saved Card Token Write to Any User via Webhook
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-23T10:54:10.323Z

Reserved: 2026-09-09T18:30:49.279Z

Link: CVE-2026-87979

cve-icon Vulnrichment

Updated: 2026-09-23T10:34:40.583Z

cve-icon NVD

Status : Received

Published: 2026-09-23T06:17:04.657

Modified: 2026-09-23T11:17:16.010

Link: CVE-2026-87979

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T15:15:05Z

Weaknesses