CVE-2026-87978: Paymob for WooCommerce < 4.1.14 - Unauthenticated Payment Bypass via Unverified Subscription Transaction Callback
The Paymob for WooCommerce WordPress plugin before 4.1.14 does not verify the request signature on one branch of its payment webhook, allowing unauthenticated attackers to mark arbitrary WooCommerce orders as paid without any payment.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
WooCommerce sites using Paymob for WooCommerce versions earlier than 4.1.14 are exposed. The affected path is a payment webhook branch handling subscription transaction callbacks.
What does an attacker need to exploit it?
An attacker does not need authentication or user interaction. They can exploit the unverified callback path to mark arbitrary WooCommerce orders as paid without making a payment.
What is the impact on an affected store?
The issue affects order payment integrity: arbitrary orders can be marked paid despite no payment being received. The provided data does not indicate confidentiality or availability impact.