CVE-2026-12584: Payment Gateway for Redsys & WooCommerce Lite < 7.0.2 - Unauthenticated Payment Confirmation via Unverified Inespay Callback
The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin before 7.0.2 does not verify the authenticity of incoming payment-provider notifications for one of its payment methods before marking orders as paid, allowing unauthenticated attackers to forge a payment-confirmation callback and complete their own orders without paying.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12584?
CVE-2026-12584 has a severity rating of 7.5, which is classified as high.
How do I fix CVE-2026-12584?
To fix CVE-2026-12584, update the Payment Gateway for Redsys & WooCommerce Lite plugin to version 7.0.2 or higher.
What is CVE-2026-12584 about?
CVE-2026-12584 involves unauthenticated payment confirmation due to the lack of verification of payment-provider notifications in the specified plugin.
Who is affected by CVE-2026-12584?
Users of the Payment Gateway for Redsys & WooCommerce Lite plugin versions prior to 7.0.2 are affected by CVE-2026-12584.
What could happen if CVE-2026-12584 is exploited?
If exploited, CVE-2026-12584 allows attackers to forge payment confirmations, potentially leading to unauthorized payments being marked as completed.