Skip to main content
Vulnerability Database/CVE-2026-87979

CVE-2026-87979: Paymob for WooCommerce Auth Bypass Flaw

CVE-2026-87979 is an authentication bypass vulnerability in the Paymob for WooCommerce WordPress plugin that lets attackers manipulate card tokens and enumerate user accounts. This article covers technical details, affected versions, security impact, and mitigation strategies.

Published:

CVE-2026-87979 Overview

CVE-2026-87979 affects the Paymob for WooCommerce WordPress plugin in versions prior to 4.1.14. The plugin fails to verify the request signature on the card-token branch of its payment webhook. Unauthenticated attackers can write a card-token record to any user's account and enumerate registered accounts on the target site. The weakness is classified as Missing Authorization [CWE-862] and is reachable over the network without user interaction.

Critical Impact

Unauthenticated attackers can inject arbitrary card-token records into any user account and enumerate valid user accounts on affected WooCommerce stores.

Affected Products

  • Paymob for WooCommerce WordPress plugin versions prior to 4.1.14
  • WordPress sites running WooCommerce with the Paymob payment gateway enabled
  • E-commerce deployments exposing the plugin's payment webhook endpoint

Discovery Timeline

  • 2026-09-23 - CVE-2026-87979 published to the National Vulnerability Database
  • 2026-09-23 - Last updated in NVD database

Technical Details for CVE-2026-87979

Vulnerability Analysis

The Paymob for WooCommerce plugin exposes a payment webhook endpoint that processes multiple event branches, including a card-token branch. On this branch, the plugin does not validate the HMAC request signature that Paymob normally attaches to callback payloads. Because the endpoint accepts requests without proving they originate from the payment provider, any network-reachable attacker can craft webhook requests that the plugin will process as authentic.

The plugin then writes the supplied card-token record to the WooCommerce user account referenced in the request. Attackers can also probe user identifiers and observe response behavior to enumerate which accounts exist on the site. Integrity is affected because attacker-controlled data is written to legitimate user records, while confidentiality of stored payment data is not directly disclosed.

Root Cause

The root cause is a missing authorization and authenticity check on an internet-facing HTTP endpoint. The card-token branch of the webhook handler processes request parameters without invoking the shared signature verification routine used by other branches. This omission means the trust boundary between Paymob's servers and untrusted internet clients is not enforced for that code path.

Attack Vector

Exploitation requires only network access to the WordPress site's public webhook URL. An attacker sends an HTTP POST request that mimics a card-token callback and specifies a target WooCommerce user identifier. The plugin accepts the request, associates the attacker-supplied token with that account, and returns responses that reveal whether the referenced account exists. No credentials, session, or user interaction are required. See the WPScan Vulnerability Report for additional technical detail.

Detection Methods for CVE-2026-87979

Indicators of Compromise

  • Unexpected card-token records added to WooCommerce user profiles that were not initiated by legitimate checkout flows
  • Webhook POST requests to the Paymob callback endpoint originating from IP addresses outside Paymob's published ranges
  • High-volume, sequential requests to the payment webhook that iterate through user or order identifiers

Detection Strategies

  • Inspect web server access logs for repeated POST requests to the Paymob webhook path, especially those referencing many distinct user IDs in a short window
  • Correlate stored card-token creation events with corresponding successful checkout transactions and flag records lacking a matching order
  • Alert on webhook requests missing or failing HMAC signature headers where the plugin still returned a success response

Monitoring Recommendations

  • Enable WooCommerce and plugin debug logging to capture full webhook payloads and source IP metadata
  • Forward WordPress, WooCommerce, and web server logs to a centralized SIEM for behavioral analysis and long-term retention
  • Track baseline webhook request volumes per source IP and alert on statistical anomalies indicative of enumeration

How to Mitigate CVE-2026-87979

Immediate Actions Required

  • Update the Paymob for WooCommerce plugin to version 4.1.14 or later on all affected WordPress sites
  • Audit the wp_woocommerce_payment_tokens table and related metadata for card-token records that do not correspond to legitimate orders
  • Review recent access logs for suspicious activity against the Paymob webhook endpoint and investigate any anomalies

Patch Information

The vendor addressed the flaw in Paymob for WooCommerce version 4.1.14 by adding signature verification to the card-token branch of the webhook. Site operators should upgrade through the WordPress plugin manager or WP-CLI. Refer to the WPScan Vulnerability Report for the authoritative advisory.

Workarounds

  • Restrict access to the Paymob webhook endpoint at the web server or WAF layer, allowing only Paymob's published source IP ranges
  • Temporarily disable the Paymob for WooCommerce plugin if upgrading immediately is not feasible and payments can be routed through an alternate gateway
  • Add a WAF rule to reject POST requests to the webhook URL that lack the expected Paymob signature header
bash
# Example nginx configuration restricting the Paymob webhook to trusted source ranges
location ~* /wc-api/paymob {
    allow 203.0.113.0/24;   # Replace with Paymob's published IP ranges
    deny all;
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.