rootpwn

medium · CVSS v3 5.3 · EPSS 0.00184

CVE-2026-92430

The Rede Itaú for WooCommerce WordPress plugin before version 5.4.7 fails to authenticate incoming PIX payment webhooks. This flaw allows un

Overview

The Rede Itaú for WooCommerce WordPress plugin before version 5.4.7 fails to authenticate incoming PIX payment webhooks. This flaw allows unauthenticated attackers to falsely mark pending orders as paid without completing any payment. It matters because it directly impacts e-commerce revenue integrity and order fulfillment processes.

Description

The Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit WordPress plugin before 5.4.7 does not verify the authenticity of its PIX payment webhook before updating an order's status, allowing unauthenticated attackers to mark a pending order as paid without paying.

Impact

The vulnerability primarily impacts confidentiality and integrity, specifically threatening business revenue by enabling fraudulent order status updates. Affected parties include online merchants using the vulnerable plugin versions for payment processing. Unauthorized actors can exploit this to obtain goods or services without remitting payment. No direct system compromise or data exfiltration is associated with this flaw.

Remediation

Update the Rede Itaú for WooCommerce plugin to version 5.4.7 or higher immediately. If updating is not immediately possible, temporarily disable the PIX payment gateway integration or implement IP-based access control restrictions for incoming webhook endpoints to trusted provider networks.

Risk context

This vulnerability is rated as medium severity with a CVSS v3 score of 5.3 and a low EPSS score of 0.00184. While the likelihood of widespread automated exploitation may be low, the financial impact to affected merchants necessitates prompt patching.

Affected products

  • Rede Itaú for WooCommerce Plugin

Scores

Severity
medium
CVSS v2
5
CVSS v3
5.3
CVSS v4
EPSS
0.00184

wordpress woocommerce payment-bypass webhook unauthenticated plugin defensive-analysis

← All CVEs