What the vulnerability does
01Description
The Rede Itaú for WooCommerce plugin for WordPress is vulnerable to order status manipulation due to insufficient verification of data authenticity in all versions up to, and including, 5.1.2. This is due to the plugin failing to verify the authenticity of payment callbacks. This makes it possible for unauthenticated attackers to manipulate WooCommerce order statuses, either marking unpaid orders as paid, or failed.
Explanation of Vulnerability in Simple Terms
02Summary
The Rede Itaú for WooCommerce payment plugin contains an integrity vulnerability affecting versions up to 5.1.2. An attacker on the network can modify data in transit without authentication or user interaction. The vulnerability does not expose sensitive information or disrupt service availability, but allows tampering with payment-related communications or transaction details.
What an attacker can do
03Attacker Capabilities
Modify payment data or transaction information in transit without authentication.
Potential impact on your site
04Site Impact
Payment transactions or order data could be altered by an attacker, potentially affecting order integrity and customer trust.
Conditions required to exploit
05Prerequisites
Network access to the site; no authentication or user interaction required.
Key dates
06Disclosure timeline
January 16, 2026
CVE published
April 8, 2026
Record updated