PT-2026-3226 · Unknown+1 · Woocommerce+1
CVE-2026-0939
·
Publicado
2026-01-16
·
Atualizado
2026-01-16
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Rede Itaú for WooCommerce plugin for WordPress versions up to and including 5.1.2
Description
The Rede Itaú for WooCommerce plugin for WordPress has a flaw related to insufficient verification of payment callback data. This allows unauthenticated attackers to manipulate WooCommerce order statuses, potentially marking unpaid orders as paid or failed. The issue stems from the plugin's failure to confirm the authenticity of payment callbacks.
Recommendations
Update the Rede Itaú for WooCommerce plugin to a version later than 5.1.2.
Correção
Insufficient Verification of Data Authenticity
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Rede Itaú For Woocommerce
Woocommerce