PT-2026-33269 · WordPress · Payment Gateway For Redsys & Woocommerce Lite
Published
2026-04-16
·
Updated
2026-04-16
·
CVE-2026-5050
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Payment Gateway for Redsys & WooCommerce Lite versions prior to 7.0.1
Description
The plugin is subject to improper verification of cryptographic signatures. The
successful request() handlers calculate a local signature but fail to validate the Ds Signature from the request before accepting payment status within the Redsys, Bizum, and Google Pay gateway flows. This allows unauthenticated attackers who possess a valid order key and order amount to forge payment callback data, marking pending orders as paid and potentially obtaining products or services without payment.Recommendations
Update to a version later than 7.0.0.
Fix
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Payment Gateway For Redsys & Woocommerce Lite