WordPress Plugin Vulnerabilities
Payment Gateway for Redsys & WooCommerce Lite < 7.0.1 - Improper Verification of Cryptographic Signature to Unauthenticated Payment Status Manipulation
Description
The plugin is vulnerable to Improper Verification of Cryptographic Signature due to successful_request() handlers calculating a local signature but not validating Ds_Signature from the request before accepting payment status across the Redsys, Bizum, and Google Pay gateway flows. This makes it possible for unauthenticated attackers to forge payment callback data and mark pending orders as paid when they know a valid order key and order amount, potentially allowing checkout completion and product or service fulfillment without a successful payment.
Affects Plugins
References
Classification
Type
IDOR
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Nguyen Ngoc Duc (duc193)
Verified
No
WPVDB ID
Timeline
Publicly Published
2026-04-15 (about 2 months ago)
Added
2026-04-15 (about 2 months ago)
Last Updated
2026-04-15 (about 2 months ago)