medium · CVSS v3 5.3
CVE-2026-87978
The Paymob for WooCommerce WordPress plugin before 4.1.14 does not verify the request signature on one branch of its pay…
Description
The Paymob for WooCommerce WordPress plugin before 4.1.14 does not verify the request signature on one branch of its payment webhook, allowing unauthenticated attackers to mark arbitrary WooCommerce orders as paid without any payment.
Scores
- Severity
- medium
- CVSS v2
- 5
- CVSS v3
- 5.3
- CVSS v4
- —
- EPSS
- —