WordPress Plugin Vulnerabilities
CorvusPay WooCommerce Payment Gateway < 2.7.5 - Unauthenticated Improper Verification of Cryptographic Signature to Payment Bypass via /wp-json/corvuspay/success/ REST Endpoint
Description
The plugin does not properly verify the cryptographic signature on its payment-success callback: the verification result is computed but never enforced, so the callback completes the order regardless of the signature's validity. This makes it possible for unauthenticated attackers to mark any pending WooCommerce order as fully paid by sending a request with an arbitrary or forged signature, obtaining goods or services without payment. As order identifiers are sequential, victim orders are trivially enumerable.
Affects Plugins
References
Miscellaneous
Original Researcher
Valatty
Verified
No
WPVDB ID
Timeline
Publicly Published
2026-07-08 (about 2 months ago)
Added
2026-07-08 (about 2 months ago)
Last Updated
2026-07-08 (about 2 months ago)