PT-2026-33269 · WordPress · Payment Gateway For Redsys & Woocommerce Lite

Published

2026-04-16

·

Updated

2026-04-16

·

CVE-2026-5050

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Payment Gateway for Redsys & WooCommerce Lite versions prior to 7.0.1
Description The plugin is subject to improper verification of cryptographic signatures. The successful request() handlers calculate a local signature but fail to validate the Ds Signature from the request before accepting payment status within the Redsys, Bizum, and Google Pay gateway flows. This allows unauthenticated attackers who possess a valid order key and order amount to forge payment callback data, marking pending orders as paid and potentially obtaining products or services without payment.
Recommendations Update to a version later than 7.0.0.

Fix

Improper Verification of Cryptographic Signature

Weakness Enumeration

Related Identifiers

CVE-2026-5050

Affected Products

Payment Gateway For Redsys & Woocommerce Lite