WordPress Plugin Vulnerabilities

Payment Gateway for Redsys & WooCommerce Lite < 7.0.1 - Improper Verification of Cryptographic Signature to Unauthenticated Payment Status Manipulation

Description

The plugin is vulnerable to Improper Verification of Cryptographic Signature due to successful_request() handlers calculating a local signature but not validating Ds_Signature from the request before accepting payment status across the Redsys, Bizum, and Google Pay gateway flows. This makes it possible for unauthenticated attackers to forge payment callback data and mark pending orders as paid when they know a valid order key and order amount, potentially allowing checkout completion and product or service fulfillment without a successful payment.

Affects Plugins

References

Classification

Type
IDOR
CWE
CVSS

Miscellaneous

Original Researcher
Nguyen Ngoc Duc (duc193)
Verified
No

Timeline

Publicly Published
2026-04-15 (about 2 months ago)
Added
2026-04-15 (about 2 months ago)
Last Updated
2026-04-15 (about 2 months ago)

Other