CVE-2026-12584 HIGH

CVE-2026-12584: Payment Gateway for Redsys & WooCommerce Lite < 7.0.2 - Unauthenticated Payment Confirmation via Unverified Inespay Callback

Vendor Unknown
Product Payment Gateway for Redsys & WooCommerce Lite
Published August 6, 2026
Last update August 6, 2026

CVSS base score

7.5/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

What the vulnerability does

01Description

The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin before 7.0.2 does not verify the authenticity of incoming payment-provider notifications for one of its payment methods before marking orders as paid, allowing unauthenticated attackers to forge a payment-confirmation callback and complete their own orders without paying.

Explanation of Vulnerability in Simple Terms

02Summary

A vulnerability in Payment Gateway for Redsys & WooCommerce Lite versions before 7.0.2 allows an attacker to modify payment transaction data without authentication. The flaw stems from insufficient input validation on payment parameters. An attacker can intercept and alter transaction details during processing, potentially changing payment amounts or recipient accounts. Site owners should update immediately to version 7.0.2 or later.

What an attacker can do

03Attacker Capabilities

Modify payment transaction data, including amounts or recipient accounts, without authentication.

Potential impact on your site

04Site Impact

Attackers can alter WooCommerce payment transactions, leading to financial loss or fraud.

Conditions required to exploit

05Prerequisites

Network access to the site; no authentication or user interaction required.

Key dates

06Disclosure timeline

August 6, 2026 CVE published