GHSA-9f34-8wwr-2wjqHighCVSS 7.5

The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin before 7.0.2 does not verify...

Published
August 7, 2026
Last Modified
August 7, 2026

🔗 CVE IDs covered (1)

📋 Description

The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin before 7.0.2 does not verify the authenticity of incoming payment-provider notifications for one of its payment methods before marking orders as paid, allowing unauthenticated attackers to forge a payment-confirmation callback and complete their own orders without paying.

🔗 References (3)