Skip to main content
Vulnerability Database/CVE-2026-87981

CVE-2026-87981: Paymob WooCommerce Privilege Escalation

CVE-2026-87981 is a privilege escalation flaw in Paymob for WooCommerce that allows contributors to modify payment gateway settings and credentials. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-87981 Overview

CVE-2026-87981 is a missing authorization vulnerability [CWE-862] in the Paymob for WooCommerce WordPress plugin versions prior to 4.1.14. The plugin fails to perform capability checks on several admin AJAX actions that manage its payment-gateway configuration. Authenticated users with contributor-level access can invoke these actions to delete, wipe, or modify the gateway configuration, including stored payment credentials. The issue affects the integrity and availability of payment processing on impacted WooCommerce stores and can expose sensitive credential data.

Critical Impact

Low-privileged contributor accounts can tamper with or wipe the Paymob payment-gateway configuration, disrupting checkout and exposing stored payment credentials.

Affected Products

  • Paymob for WooCommerce WordPress plugin versions before 4.1.14
  • WordPress sites running WooCommerce with the vulnerable Paymob integration
  • Any environment permitting contributor-level (or higher) authenticated user registration

Discovery Timeline

  • 2026-09-23 - CVE-2026-87981 published to NVD
  • 2026-09-23 - Last updated in NVD database

Technical Details for CVE-2026-87981

Vulnerability Analysis

The Paymob for WooCommerce plugin registers multiple admin AJAX actions that manage payment-gateway configuration. These handlers process requests through the WordPress admin-ajax.php endpoint but omit current_user_can() capability checks before executing privileged operations. Any authenticated user, including those with the contributor role, can invoke the endpoints and modify gateway state.

The attacker's impact includes deleting configuration, wiping stored settings, and altering payment credentials. Overwriting credentials can redirect payment processing to attacker-controlled Paymob accounts or break the checkout flow entirely. Because credentials may also be read back through configuration responses, disclosure of sensitive gateway secrets is possible.

The vulnerability requires authentication but not administrative privileges, which lowers the barrier significantly on sites that allow open registration or use contributor workflows for guest authors.

Root Cause

The root cause is missing authorization [CWE-862] on privileged AJAX handlers. The plugin relies on nonce validation or simple is_user_logged_in() semantics without enforcing that the caller holds an administrative capability such as manage_woocommerce or manage_options. WordPress does not enforce role-based access on wp_ajax_* hooks by default, so the check must be implemented in each handler.

Attack Vector

An attacker authenticates to the target WordPress site using a contributor-level account. The attacker then issues crafted POST requests to admin-ajax.php, targeting the vulnerable Paymob AJAX action names. Requests include a valid AJAX nonce obtained from the authenticated session. The handler executes without verifying the caller's role and performs the requested configuration change. Refer to the WPScan Vulnerability Overview for handler-specific technical details.

Detection Methods for CVE-2026-87981

Indicators of Compromise

  • Unexpected changes or resets to Paymob gateway settings in the WooCommerce admin dashboard
  • Payment failures or transactions routed to unfamiliar Paymob merchant identifiers
  • admin-ajax.php POST requests from low-privileged user sessions targeting Paymob action names
  • Recent contributor or subscriber account creation followed by AJAX activity to plugin endpoints

Detection Strategies

  • Review web server access logs for authenticated POST requests to /wp-admin/admin-ajax.php where the action parameter references Paymob configuration handlers
  • Correlate WordPress user role with AJAX action usage to flag non-administrative accounts invoking configuration endpoints
  • Audit the WooCommerce wp_options entries and Paymob settings for unexpected modification timestamps

Monitoring Recommendations

  • Enable WordPress audit logging to record settings changes, user role activity, and AJAX invocations
  • Alert on any modification to payment gateway credentials outside change windows
  • Monitor for new user registrations at contributor level and above, particularly on sites with open registration

How to Mitigate CVE-2026-87981

Immediate Actions Required

  • Upgrade the Paymob for WooCommerce plugin to version 4.1.14 or later
  • Rotate all Paymob API credentials and merchant keys stored in the plugin configuration
  • Audit existing user accounts and remove or downgrade untrusted contributor, author, and editor accounts
  • Review recent payment transactions for signs of redirection to attacker-controlled accounts

Patch Information

The vendor addressed the issue in Paymob for WooCommerce version 4.1.14 by adding capability checks to the affected admin AJAX handlers. Site operators should update through the WordPress plugin manager or by deploying the patched release from the plugin repository. See the WPScan Vulnerability Overview for the vendor advisory reference.

Workarounds

  • Temporarily disable the Paymob for WooCommerce plugin until the patched version is deployed
  • Disable open user registration or restrict the default new-user role to subscriber
  • Restrict admin-ajax.php access through a web application firewall rule that blocks Paymob action names for non-administrative sessions
bash
# Update the plugin via WP-CLI
wp plugin update paymob-woocommerce --version=4.1.14

# Verify installed version
wp plugin get paymob-woocommerce --field=version

# Restrict default registration role in wp-config.php or Settings > General
# Ensure 'Anyone can register' is disabled and default role is 'subscriber'

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.