CVE-2026-103329: Super Payments < 1.43.1 - Unauthenticated Payment Confirmation Forgery via Webhook Signature
The Super Payments WordPress plugin before 1.43.1 does not properly verify the authenticity of incoming payment webhook notifications, as the signing key used to validate their signature is empty by default, allowing unauthenticated attackers to forge a valid signature and mark arbitrary WooCommerce orders as paid without payment.
Affected Software
Event History
Frequently Asked Questions
Which sites are exposed to this issue?
Sites using the Super Payments WordPress plugin before version 1.43.1 are exposed when the webhook signing key remains empty, which is the default configuration described for the affected plugin.
What does an attacker need to exploit it?
An attacker can exploit the issue remotely without authentication or user interaction. They can forge a webhook signature and submit a payment notification that marks an arbitrary WooCommerce order as paid without an actual payment.
What should be done if the plugin cannot be updated immediately?
Configure a non-empty webhook signing key so incoming payment webhook signatures cannot be validated using the default empty key. Updating to version 1.43.1 or later addresses the affected version range.