CVE-2026-84091 Overview
CVE-2026-84091 is an authentication bypass vulnerability in the SUMIT Payment Gateway for WooCommerce WordPress plugin versions before 4.0.0. The plugin fails to verify with the payment provider that incoming payment notifications are genuine before marking the associated order as paid. Unauthenticated attackers can send forged notifications to mark pending orders as paid without completing any actual payment. The flaw maps to improper authentication [CWE-287] and affects the integrity of e-commerce transactions on merchant sites using the plugin.
Critical Impact
Unauthenticated attackers can mark WooCommerce orders as paid without submitting payment, resulting in fraudulent order fulfillment and financial loss to merchants.
Affected Products
- SUMIT Payment Gateway for WooCommerce WordPress plugin versions before 4.0.0
- WooCommerce storefronts using the SUMIT payment integration
- WordPress sites accepting payments through the SUMIT gateway
Discovery Timeline
- 2026-09-23 - CVE-2026-84091 published to NVD
- 2026-09-23 - Last updated in NVD database
Technical Details for CVE-2026-84091
Vulnerability Analysis
The SUMIT Payment Gateway plugin implements a callback endpoint that receives payment notifications from the payment provider. When a notification arrives, the plugin updates the corresponding WooCommerce order status to paid. The vulnerability stems from the plugin trusting the notification payload without validating its origin.
Because the plugin does not perform a server-to-server verification call back to the SUMIT payment provider, any unauthenticated actor can craft a request to the notification endpoint referencing an order ID. The plugin accepts the request and transitions the order to paid status. Merchants then process, ship, or deliver goods and services with no funds received.
Root Cause
The root cause is missing authentication of the payment notification source [CWE-287]. Secure payment gateway integrations require one or more of the following: cryptographic signature validation on the callback payload, shared-secret HMAC verification, IP allowlisting of the provider's notification servers, or an outbound API call to the payment provider to confirm the transaction status. The affected plugin versions implement none of these controls before writing the paid state.
Attack Vector
The attack is remote, network-based, and requires no authentication or user interaction. An attacker identifies a target WooCommerce store using the SUMIT gateway, places an order to obtain a valid pending order identifier, and then sends a crafted HTTP request to the plugin's payment notification endpoint referencing that order. The order transitions to paid without any funds moving. Refer to the WPScan Vulnerability Report for endpoint-level details.
Detection Methods for CVE-2026-84091
Indicators of Compromise
- Orders transitioning from pending to processing or completed without a corresponding transaction record at the SUMIT payment provider.
- Payment notification requests arriving from IP addresses outside the documented SUMIT provider ranges.
- WooCommerce order notes referencing paid status while merchant reconciliation reports show no matching settlement.
Detection Strategies
- Reconcile WooCommerce order status changes against the SUMIT merchant dashboard on a scheduled basis to surface unmatched paid orders.
- Review web server access logs for unauthenticated POST requests to the SUMIT callback path.
- Alert on order fulfillment activity for orders lacking a verified provider-side transaction ID.
Monitoring Recommendations
- Enable WordPress and WooCommerce audit logging to capture order status transitions with source IP and request metadata.
- Forward web server and application logs to a centralized SIEM for correlation between callback requests and provider settlement records.
- Configure alerts for spikes in order status changes to paid outside normal transaction volume patterns.
How to Mitigate CVE-2026-84091
Immediate Actions Required
- Update the SUMIT Payment Gateway for WooCommerce plugin to version 4.0.0 or later on all affected WordPress installations.
- Audit orders marked as paid since the plugin was installed and reconcile against SUMIT provider settlement records.
- Hold fulfillment on any orders that cannot be reconciled with a confirmed provider-side transaction.
Patch Information
The plugin vendor addressed the issue in version 4.0.0, which introduces verification of payment notifications with the SUMIT provider before marking orders as paid. Merchants should upgrade through the WordPress plugin repository. See the WPScan Vulnerability Report for advisory details.
Workarounds
- Restrict access to the plugin's payment notification endpoint at the web server or WAF layer, allowlisting only documented SUMIT provider IP addresses.
- Disable the SUMIT payment gateway in WooCommerce settings until the plugin is upgraded to 4.0.0.
- Require manual reconciliation and approval before fulfilling any order processed through the SUMIT gateway on unpatched sites.
# Example WAF rule concept: allowlist SUMIT provider IPs to the callback path
# Replace <SUMIT_PROVIDER_CIDR> with ranges published by the payment provider
location ~ ^/\?wc-api=sumit_callback$ {
allow <SUMIT_PROVIDER_CIDR>;
deny all;
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
