WordPress Plugin Vulnerabilities

Paymob for WooCommerce < 4.1.14 - Unauthenticated Payment Bypass via Unverified Subscription Transaction Callback

Description

The plugin does not verify the request signature on one branch of its payment webhook, allowing unauthenticated attackers to mark arbitrary WooCommerce orders as paid without any payment.

Proof of Concept

Affects Plugins

Fixed in 4.1.14

References

Miscellaneous

Original Researcher
Charles Vosburgh
Submitter
Charles Vosburgh
Verified
Yes

Timeline

Publicly Published
2026-09-21 (about 3 days ago)
Added
2026-09-21 (about 3 days ago)
Last Updated
2026-09-21 (about 3 days ago)

Other