CVE-2026-12584
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Summary
The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin before 7.0.2 does not verify the authenticity of incoming payment-provider notifications for one of its payment methods before marking orders as paid, allowing unauthenticated attackers to forge a payment-confirmation callback and complete their own orders without paying.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Payment Gateway for Redsys & WooCommerce Lite | 0 < 7.0.2 | affected |
Weaknesses
- CWE-345 Insufficient Verification of Data Authenticity
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.