Description
The Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit WordPress plugin before 5.4.7 does not verify the authenticity of its PIX payment webhook before updating an order's status, allowing unauthenticated attackers to mark a pending order as paid without paying.
Published: 2026-09-19
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated Order Status Manipulation
Action: Patch
AI Analysis

Impact

The vulnerability allows an unauthenticated attacker to trigger the Rede Itaú plugin’s PIX payment webhook without verification, enabling the manipulation of an order’s status from pending to paid. This can cause the WooCommerce store to credit orders that have not been paid, resulting in revenue loss, compromised financial integrity, and increased fraud risk.

Affected Systems

The affected component is the Rede Itaú for WooCommerce – Payment PIX, Credit Card and Debit WordPress plugin prior to version 5.4.7. No specific sub‑versions are listed beyond the <5.4.7 cutoff.

Risk and Exploitability

The plugin accepts external webhook requests without authentication or signature checks, so an attacker can send an HTTP request with appropriate data to the webhook URL and change order status. Because no prior authentication is required, the vulnerability is easy to exploit. The CVSS score is 5.3, indicating moderate severity. The low EPSS score (<1%) indicates a small but non-zero exploitation probability, while it is not listed in KEV; this does not diminish the inherent risk as the impact on financial transactions is significant.

Generated by OpenCVE AI on September 20, 2026 at 00:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Rede Itaú for WooCommerce plugin to version 5.4.7 or later, which implements proper webhook authentication.
  • Temporarily disable the PIX webhook endpoint or restrict incoming traffic to trusted IP addresses until the plugin is updated.
  • Configure the plugin to validate a shared secret or signature with every webhook request, and verify that the request originates from Rede Itaú’s known servers.

Generated by OpenCVE AI on September 20, 2026 at 00:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress-extensions
Wordpress-extensions rede Itau For Woocommerce
Vendors & Products Wordpress-extensions
Wordpress-extensions rede Itau For Woocommerce

Sun, 20 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Sat, 19 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287

Sat, 19 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit WordPress plugin before 5.4.7 does not verify the authenticity of its PIX payment webhook before updating an order's status, allowing unauthenticated attackers to mark a pending order as paid without paying.
Title Rede Itaú for WooCommerce < 5.4.7 - Unauthenticated Order Status Manipulation via PIX Webhook
References

Subscriptions

Wordpress-extensions Rede Itau For Woocommerce
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-19T13:16:41.837Z

Reserved: 2026-09-16T10:08:51.566Z

Link: CVE-2026-92430

cve-icon Vulnrichment

Updated: 2026-09-19T13:10:16.263Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T07:16:34.200

Modified: 2026-09-21T13:34:57.127

Link: CVE-2026-92430

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T19:49:12Z

Weaknesses