Skip to main content
Vulnerability Database/CVE-2026-87978

CVE-2026-87978: Paymob WooCommerce Auth Bypass Vulnerability

CVE-2026-87978 is an authentication bypass flaw in Paymob for WooCommerce that lets attackers mark orders as paid without payment verification. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-87978 Overview

CVE-2026-87978 affects the Paymob for WooCommerce WordPress plugin in versions prior to 4.1.14. The plugin fails to verify the request signature on one branch of its payment webhook handler. Unauthenticated attackers can send crafted webhook requests to mark arbitrary WooCommerce orders as paid without submitting any actual payment. The flaw is categorized under Insufficient Verification of Data Authenticity [CWE-345].

Critical Impact

Remote unauthenticated attackers can manipulate order payment state, causing financial loss to merchants who fulfill orders based on falsified payment confirmations.

Affected Products

  • Paymob for WooCommerce WordPress plugin versions before 4.1.14
  • WooCommerce store deployments using the vulnerable Paymob plugin
  • WordPress sites processing payments through the affected webhook branch

Discovery Timeline

  • 2026-09-23 - CVE-2026-87978 published to NVD
  • 2026-09-23 - Last updated in NVD database

Technical Details for CVE-2026-87978

Vulnerability Analysis

The Paymob for WooCommerce plugin exposes a webhook endpoint that receives payment status callbacks from the Paymob payment gateway. Webhook integrations typically rely on a cryptographic signature (usually an HMAC) transmitted alongside the payload to prove the request originates from the legitimate payment processor. In vulnerable versions, one code branch of the webhook handler processes incoming requests without validating this signature. An attacker who reaches the webhook URL can therefore submit a payload that transitions a target order into the paid state. Merchants relying on WooCommerce order status to trigger fulfillment or digital delivery may ship goods or grant entitlements against transactions that were never funded.

Root Cause

The root cause is missing authenticity verification on a specific execution path of the webhook handler [CWE-345]. Signature validation is present on other branches but omitted on the vulnerable path, resulting in an inconsistent trust boundary between the plugin and the Paymob gateway.

Attack Vector

Exploitation requires no authentication, no user interaction, and only network access to the target WordPress site. The attacker sends an HTTP request to the plugin's public webhook endpoint containing an order identifier and status fields that map the order to a paid state. Because the vulnerable branch does not verify the request signature, WooCommerce updates the order accordingly.

// No verified proof-of-concept code is publicly available.
// Technical details are described in the WPScan advisory referenced below.

Detection Methods for CVE-2026-87978

Indicators of Compromise

  • WooCommerce orders transitioning to a paid or processing state without a corresponding transaction record in the Paymob merchant dashboard.
  • HTTP POST requests to the Paymob webhook endpoint originating from IP addresses outside Paymob's documented callback ranges.
  • Order status change events in WordPress logs that lack a preceding successful signature verification log entry.

Detection Strategies

  • Reconcile WooCommerce order records against Paymob transaction reports on a scheduled basis to surface orders marked paid without a matching gateway transaction.
  • Enable verbose logging on the Paymob plugin webhook handler and alert on requests processed through the unsigned branch.
  • Deploy web application firewall rules to log and inspect all requests to the plugin's webhook path.

Monitoring Recommendations

  • Forward WordPress and web server access logs to a centralized log platform and build detections for anomalous webhook traffic volume or geographic origin.
  • Monitor for large or rapid changes in order-paid counts that do not correlate with legitimate traffic patterns.
  • Alert security and finance teams when high-value orders transition to paid state outside of business patterns.

How to Mitigate CVE-2026-87978

Immediate Actions Required

  • Upgrade the Paymob for WooCommerce plugin to version 4.1.14 or later on all WordPress sites.
  • Audit recent WooCommerce orders against Paymob gateway records and cancel or refund any fulfillment triggered by unverified payments.
  • Restrict access to the plugin webhook endpoint using IP allowlisting for Paymob callback ranges until patching is complete.

Patch Information

The vendor addressed the issue in Paymob for WooCommerce version 4.1.14 by enforcing signature verification on all webhook processing branches. Details are documented in the WPScan Vulnerability Report.

Workarounds

  • Temporarily disable the Paymob for WooCommerce plugin if patching cannot be performed immediately and payments can be routed through an alternate gateway.
  • Configure the web server or WAF to enforce IP allowlisting on the Paymob webhook URL, permitting only documented Paymob source addresses.
  • Delay automated fulfillment for orders paid through Paymob until manual reconciliation against the gateway dashboard is completed.
bash
# Example nginx allowlist for the Paymob webhook endpoint
location ~* /wp-json/paymob/ {
    allow <paymob-ip-range>;
    deny all;
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.