WordPress Plugin Vulnerabilities
SUMIT Payment Gateway for WooCommerce < 4.0.0 - Unauthenticated Payment Confirmation Forgery via bit IPN
Description
The plugin does not verify with the payment provider that a payment notification is genuine before marking the corresponding order as paid, allowing unauthenticated users to mark a pending order paid without completing payment.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
AUTHBYPASS
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Pedro Pinho
Submitter
Pedro Pinho
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-09-17 (about 6 days ago)
Added
2026-09-17 (about 5 days ago)
Last Updated
2026-09-23 (about 2 hours ago)