CVE-2026-87979 Overview
CVE-2026-87979 affects the Paymob for WooCommerce WordPress plugin in versions prior to 4.1.14. The plugin fails to verify the request signature on the card-token branch of its payment webhook. Unauthenticated attackers can write a card-token record to any user's account and enumerate registered accounts on the target site. The weakness is classified as Missing Authorization [CWE-862] and is reachable over the network without user interaction.
Critical Impact
Unauthenticated attackers can inject arbitrary card-token records into any user account and enumerate valid user accounts on affected WooCommerce stores.
Affected Products
- Paymob for WooCommerce WordPress plugin versions prior to 4.1.14
- WordPress sites running WooCommerce with the Paymob payment gateway enabled
- E-commerce deployments exposing the plugin's payment webhook endpoint
Discovery Timeline
- 2026-09-23 - CVE-2026-87979 published to the National Vulnerability Database
- 2026-09-23 - Last updated in NVD database
Technical Details for CVE-2026-87979
Vulnerability Analysis
The Paymob for WooCommerce plugin exposes a payment webhook endpoint that processes multiple event branches, including a card-token branch. On this branch, the plugin does not validate the HMAC request signature that Paymob normally attaches to callback payloads. Because the endpoint accepts requests without proving they originate from the payment provider, any network-reachable attacker can craft webhook requests that the plugin will process as authentic.
The plugin then writes the supplied card-token record to the WooCommerce user account referenced in the request. Attackers can also probe user identifiers and observe response behavior to enumerate which accounts exist on the site. Integrity is affected because attacker-controlled data is written to legitimate user records, while confidentiality of stored payment data is not directly disclosed.
Root Cause
The root cause is a missing authorization and authenticity check on an internet-facing HTTP endpoint. The card-token branch of the webhook handler processes request parameters without invoking the shared signature verification routine used by other branches. This omission means the trust boundary between Paymob's servers and untrusted internet clients is not enforced for that code path.
Attack Vector
Exploitation requires only network access to the WordPress site's public webhook URL. An attacker sends an HTTP POST request that mimics a card-token callback and specifies a target WooCommerce user identifier. The plugin accepts the request, associates the attacker-supplied token with that account, and returns responses that reveal whether the referenced account exists. No credentials, session, or user interaction are required. See the WPScan Vulnerability Report for additional technical detail.
Detection Methods for CVE-2026-87979
Indicators of Compromise
- Unexpected card-token records added to WooCommerce user profiles that were not initiated by legitimate checkout flows
- Webhook POST requests to the Paymob callback endpoint originating from IP addresses outside Paymob's published ranges
- High-volume, sequential requests to the payment webhook that iterate through user or order identifiers
Detection Strategies
- Inspect web server access logs for repeated POST requests to the Paymob webhook path, especially those referencing many distinct user IDs in a short window
- Correlate stored card-token creation events with corresponding successful checkout transactions and flag records lacking a matching order
- Alert on webhook requests missing or failing HMAC signature headers where the plugin still returned a success response
Monitoring Recommendations
- Enable WooCommerce and plugin debug logging to capture full webhook payloads and source IP metadata
- Forward WordPress, WooCommerce, and web server logs to a centralized SIEM for behavioral analysis and long-term retention
- Track baseline webhook request volumes per source IP and alert on statistical anomalies indicative of enumeration
How to Mitigate CVE-2026-87979
Immediate Actions Required
- Update the Paymob for WooCommerce plugin to version 4.1.14 or later on all affected WordPress sites
- Audit the wp_woocommerce_payment_tokens table and related metadata for card-token records that do not correspond to legitimate orders
- Review recent access logs for suspicious activity against the Paymob webhook endpoint and investigate any anomalies
Patch Information
The vendor addressed the flaw in Paymob for WooCommerce version 4.1.14 by adding signature verification to the card-token branch of the webhook. Site operators should upgrade through the WordPress plugin manager or WP-CLI. Refer to the WPScan Vulnerability Report for the authoritative advisory.
Workarounds
- Restrict access to the Paymob webhook endpoint at the web server or WAF layer, allowing only Paymob's published source IP ranges
- Temporarily disable the Paymob for WooCommerce plugin if upgrading immediately is not feasible and payments can be routed through an alternate gateway
- Add a WAF rule to reject POST requests to the webhook URL that lack the expected Paymob signature header
# Example nginx configuration restricting the Paymob webhook to trusted source ranges
location ~* /wc-api/paymob {
allow 203.0.113.0/24; # Replace with Paymob's published IP ranges
deny all;
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
