Skip to main content
Vulnerability Database/CVE-2026-75959

CVE-2026-75959: GoPay for WooCommerce SQL Injection Flaw

CVE-2026-75959 is a SQL injection vulnerability in GoPay for WooCommerce plugin allowing shop managers to extract sensitive database information. This post covers technical details, affected versions, and mitigation.

Published:

CVE-2026-75959 Overview

CVE-2026-75959 is a SQL injection vulnerability in the GoPay for WooCommerce plugin for WordPress. The flaw exists in the log_table_filter parameter and affects all versions up to and including 1.0.36. The plugin fails to properly escape user-supplied input and does not use prepared statements on the underlying SQL query. Authenticated attackers holding shop manager privileges or higher can append additional SQL statements to existing queries. Successful exploitation allows extraction of sensitive data from the WordPress database, including user records and order information. The vulnerability is tracked under CWE-89 (Improper Neutralization of Special Elements used in an SQL Command).

Critical Impact

Authenticated shop managers can exfiltrate arbitrary database contents, including customer data and administrative credentials stored in WordPress tables.

Affected Products

  • GoPay for WooCommerce plugin for WordPress, versions up to and including 1.0.36
  • WordPress sites running WooCommerce with the GoPay payment gateway enabled
  • Any deployment granting shop manager or higher roles to non-trusted users

Discovery Timeline

  • 2026-09-19 - CVE-2026-75959 published to the National Vulnerability Database
  • 2026-09-21 - Last updated in NVD database

Technical Details for CVE-2026-75959

Vulnerability Analysis

The vulnerability resides in the plugin's administrative log viewer. Source references from the WordPress plugin repository point to admin/class-gopay-gateway-admin.php and admin/views/log.php as the affected files. The log_table_filter parameter is passed from the admin log view directly into a SQL query without proper sanitization or parameterization.

Because the query is constructed via string concatenation, an attacker can break out of the intended context and append arbitrary SQL. The impact is limited to confidentiality: attackers can read data from any table the WordPress database user can access, but the CVSS vector indicates no impact to integrity or availability.

Exploitation requires an authenticated session with shop manager privileges or higher, which reduces the exposure to environments where such accounts are provisioned for merchants, staff, or third parties.

Root Cause

The root cause is insufficient escaping of the log_table_filter request parameter combined with the absence of $wpdb->prepare() usage on the existing SQL query. WordPress provides prepare() as the standard mechanism for safely binding parameters, but the affected code paths concatenate the filter value directly into the query string.

Attack Vector

Exploitation occurs over the network through the WordPress administrative interface. An authenticated attacker submits a crafted value for log_table_filter while accessing the GoPay gateway log view. The injected SQL is appended to the existing query, allowing UNION-based or boolean-based extraction of records from the wp_users, wp_usermeta, wp_options, and WooCommerce order tables.

The vulnerability is not exploitable without valid credentials. There is no public proof-of-concept exploit or CISA KEV listing at the time of publication. See the Wordfence Vulnerability Report for additional analysis and the GoPay Gateway Admin Log View source references for the affected code.

Detection Methods for CVE-2026-75959

Indicators of Compromise

  • HTTP requests to the WordPress admin containing log_table_filter parameter values with SQL syntax such as UNION, SELECT, --, /*, or encoded variants
  • Unexpected access to the GoPay gateway log admin page (admin.php?page=gopay-gateway) from shop manager accounts
  • Database error messages surfaced in admin responses referencing malformed SQL near the filter clause
  • Anomalous outbound data volume following administrative logins by shop manager accounts

Detection Strategies

  • Inspect WordPress access logs and web application firewall telemetry for SQL keywords in the log_table_filter query string parameter
  • Correlate authenticated admin sessions with subsequent large SELECT queries against wp_users and wp_usermeta in database audit logs
  • Enable WordPress database query logging temporarily to identify concatenated payloads originating from the GoPay admin page

Monitoring Recommendations

  • Forward WordPress and web server logs to a centralized analytics platform for retention and correlation
  • Alert on shop manager account logins that immediately access payment gateway admin views
  • Monitor for creation of new administrator accounts or modification of user role capabilities following shop manager activity

How to Mitigate CVE-2026-75959

Immediate Actions Required

  • Update the GoPay for WooCommerce plugin to a version newer than 1.0.36 as soon as a patched release is available from the vendor
  • Audit the list of accounts holding shop manager or higher roles and revoke privileges that are not strictly required
  • Rotate credentials for administrative WordPress accounts and any accounts sharing passwords with the affected site
  • Review WooCommerce order and customer data for signs of unauthorized access or export

Patch Information

A fixed version above 1.0.36 should be obtained from the plugin's WordPress.org listing once published. Verify the changelog references the SQL injection fix in the log viewer. Review the Wordfence Vulnerability Report for the latest patch status and version guidance.

Workarounds

  • Deactivate the GoPay for WooCommerce plugin until a patched version is installed if payment gateway functionality can be temporarily suspended
  • Restrict access to the WordPress admin interface using IP allow-listing at the web server or WAF layer
  • Deploy a web application firewall rule blocking requests where the log_table_filter parameter contains SQL metacharacters such as single quotes, semicolons, or UNION keywords
  • Reduce the number of shop manager and administrator accounts and enforce multi-factor authentication for all remaining privileged users
bash
# Example WAF rule concept (ModSecurity-style) to block SQLi in the vulnerable parameter
SecRule ARGS:log_table_filter "@rx (?i)(union(\s|\+)+select|--|/\*|;|\bselect\b.*\bfrom\b)" \
  "id:1075959,phase:2,deny,status:403,msg:'CVE-2026-75959 GoPay log_table_filter SQLi attempt'"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.