CVE-2026-107420: WordPress Pay With MetaMask For WooCommerce – Cryptocurrency Payment Gateway plugin <= 1.7.2 - Bypass Vulnerability vulnerability
Unauthenticated Bypass Vulnerability in Pay With MetaMask For WooCommerce – Cryptocurrency Payment Gateway <= 1.7.2 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Pay With MetaMask For WooCommerce – Cryptocurrency Payment Gatewayto a version that resolves this vulnerability.Fixed in 1.7.3
Event History
Frequently Asked Questions
Who can exploit this issue?
The issue is unauthenticated, so an attacker does not need a WordPress account or existing privileges to exploit it. Network access to the affected site is implied by the AV:N vector.
Which installations are affected?
Installations using Pay With MetaMask For WooCommerce – Cryptocurrency Payment Gateway version 1.7.2 or earlier are affected according to the available data. The data does not state whether the vulnerable behavior is enabled in the default configuration.
What is the expected security impact?
The reported impact is integrity-only and low: the CVSS vector specifies I:L, with no confidentiality or availability impact. The available data does not identify the specific action or control that can be bypassed.