PT-2026-26863 · Automattic+1 · Woocommerce+1
Ronnachai Chaipha
+1
·
Publicado
2026-03-21
·
Atualizado
2026-03-21
·
CVE-2026-3641
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Appmax plugin for WordPress versions up to and including 1.0.3
Description
The software contains a flaw due to a lack of proper input validation in a public REST API webhook endpoint. The endpoint, located at
/webhook-system, does not implement webhook signature validation, secret verification, or authentication mechanisms to confirm the origin of incoming webhook requests. The plugin processes untrusted data from the event and data parameters without verifying authenticity. This allows attackers to manipulate WooCommerce orders, including modifying their status (processing, refunded, cancelled, or pending) and creating new orders with arbitrary data. Attackers can also create new WooCommerce products with attacker-controlled details like names, descriptions, and prices, and write arbitrary values to order post metadata by spoofing legitimate webhook events.Recommendations
Versions prior to 1.0.4 should not be used.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Appmax Plugin
Woocommerce