WordPress Plugin Vulnerabilities

Payment Gateway for Redsys & WooCommerce Lite < 7.0.2 - Unauthenticated Payment Confirmation via Unverified Inespay Callback

Description

The plugin does not verify the authenticity of incoming payment-provider notifications for one of its payment methods before marking orders as paid, allowing unauthenticated attackers to forge a payment-confirmation callback and complete their own orders without paying.

Proof of Concept

Affects Plugins

References

Miscellaneous

Original Researcher
Shivamani Vastrala
Submitter
Shivamani Vastrala
Verified
Yes

Timeline

Publicly Published
2026-06-29 (about 1 month ago)
Added
2026-06-29 (about 1 month ago)
Last Updated
2026-08-07 (about 3 hours ago)

Other