CVE-2026-28180 MEDIUM

CVE-2026-28180: WordPress Mercado Pago payments for WooCommerce plugin <= 8.9.0 - Insecure Direct Object References (IDOR) vulnerability

Vendor Mercado Pago
Product Mercado Pago payments for WooCommerce
Weakness CWE-639 · IDOR
Published August 6, 2026
Last update August 6, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pago payments for WooCommerce <= 8.9.0 versions.

Explanation of Vulnerability in Simple Terms

02Summary

The Mercado Pago payments plugin for WooCommerce versions up to 8.9.0 contains an authorization bypass vulnerability. An attacker can read sensitive payment information by manipulating user-controlled parameters in API requests. No authentication or user interaction is required. Site owners should update to a version newer than 8.9.0 immediately.

What an attacker can do

03Attacker Capabilities

Read sensitive payment and customer data without authentication.

Potential impact on your site

04Site Impact

Customer payment details and transaction records may be exposed to unauthorized access.

Conditions required to exploit

05Prerequisites

Network access to the site; no authentication required.

Key dates

06Disclosure timeline

August 6, 2026 CVE published
August 6, 2026 Record updated

Related vulnerabilities

08Related CVE