What the vulnerability does
01Description
The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin before 7.0.2 does not verify the authenticity of incoming payment-provider notifications for one of its payment methods before marking orders as paid, allowing unauthenticated attackers to forge a payment-confirmation callback and complete their own orders without paying.
Explanation of Vulnerability in Simple Terms
02Summary
A vulnerability in Payment Gateway for Redsys & WooCommerce Lite versions before 7.0.2 allows an attacker to modify payment transaction data without authentication. The flaw stems from insufficient input validation on payment parameters. An attacker can intercept and alter transaction details during processing, potentially changing payment amounts or recipient accounts. Site owners should update immediately to version 7.0.2 or later.
What an attacker can do
03Attacker Capabilities
Modify payment transaction data, including amounts or recipient accounts, without authentication.
Potential impact on your site
04Site Impact
Attackers can alter WooCommerce payment transactions, leading to financial loss or fraud.
Conditions required to exploit
05Prerequisites
Network access to the site; no authentication or user interaction required.
Key dates
06Disclosure timeline
August 6, 2026
CVE published