WordPress Plugin Vulnerabilities

Paymob for WooCommerce < 4.1.14 - Unauthenticated Saved Card Token Write to Any User via Webhook

Description

The plugin does not verify the request signature on the card-token branch of its payment webhook, allowing unauthenticated attackers to write a card-token record to any user's account and to enumerate registered accounts.

Proof of Concept

Affects Plugins

Fixed in 4.1.14

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Salúa Es-sair
Submitter
Salúa Es-sair
Verified
Yes

Timeline

Publicly Published
2026-09-21 (about 2 days ago)
Added
2026-09-21 (about 1 day ago)
Last Updated
2026-09-21 (about 1 day ago)

Other