medium · CVSS v3 5.3 · EPSS 0.00184
CVE-2026-92430
The Rede Itaú for WooCommerce WordPress plugin before version 5.4.7 fails to authenticate incoming PIX payment webhooks. This flaw allows un
Overview
The Rede Itaú for WooCommerce WordPress plugin before version 5.4.7 fails to authenticate incoming PIX payment webhooks. This flaw allows unauthenticated attackers to falsely mark pending orders as paid without completing any payment. It matters because it directly impacts e-commerce revenue integrity and order fulfillment processes.
Description
The Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit WordPress plugin before 5.4.7 does not verify the authenticity of its PIX payment webhook before updating an order's status, allowing unauthenticated attackers to mark a pending order as paid without paying.
Impact
The vulnerability primarily impacts confidentiality and integrity, specifically threatening business revenue by enabling fraudulent order status updates. Affected parties include online merchants using the vulnerable plugin versions for payment processing. Unauthorized actors can exploit this to obtain goods or services without remitting payment. No direct system compromise or data exfiltration is associated with this flaw.
Remediation
Update the Rede Itaú for WooCommerce plugin to version 5.4.7 or higher immediately. If updating is not immediately possible, temporarily disable the PIX payment gateway integration or implement IP-based access control restrictions for incoming webhook endpoints to trusted provider networks.
Risk context
This vulnerability is rated as medium severity with a CVSS v3 score of 5.3 and a low EPSS score of 0.00184. While the likelihood of widespread automated exploitation may be low, the financial impact to affected merchants necessitates prompt patching.
Affected products
- Rede Itaú for WooCommerce Plugin
Scores
- Severity
- medium
- CVSS v2
- 5
- CVSS v3
- 5.3
- CVSS v4
- —
- EPSS
- 0.00184