PT-2026-26863 · Automattic+1 · Woocommerce+1

Ronnachai Chaipha

+1

·

Publicado

2026-03-21

·

Atualizado

2026-03-21

·

CVE-2026-3641

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Appmax plugin for WordPress versions up to and including 1.0.3
Description The software contains a flaw due to a lack of proper input validation in a public REST API webhook endpoint. The endpoint, located at /webhook-system, does not implement webhook signature validation, secret verification, or authentication mechanisms to confirm the origin of incoming webhook requests. The plugin processes untrusted data from the event and data parameters without verifying authenticity. This allows attackers to manipulate WooCommerce orders, including modifying their status (processing, refunded, cancelled, or pending) and creating new orders with arbitrary data. Attackers can also create new WooCommerce products with attacker-controlled details like names, descriptions, and prices, and write arbitrary values to order post metadata by spoofing legitimate webhook events.
Recommendations Versions prior to 1.0.4 should not be used.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-3641

Produtos afetados

Appmax Plugin
Woocommerce