CVE-2026-87981: Paymob for WooCommerce < 4.1.14 - Contributor+ Payment Gateway Configuration Deletion and Modification via Multiple AJAX Actions
The Paymob for WooCommerce WordPress plugin before 4.1.14 does not perform a capability check on several admin AJAX actions that manage its payment-gateway configuration, allowing users with contributor-level access to delete, wipe, or modify that configuration, including the stored payment credentials.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Paymob for WooCommerceto a version that resolves this vulnerability.Fixed in 4.1.14
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated WordPress user with contributor-level access or higher can trigger the affected AJAX actions. The issue does not require administrator privileges.
What configuration can an attacker affect?
An attacker can delete, wipe, or modify Paymob payment-gateway configuration through multiple AJAX actions, including stored payment credentials.
Which plugin versions are affected?
Paymob for WooCommerce versions earlier than 4.1.14 are affected.