The Total processing card payments for WooCommerce...
Critical severity
Unreviewed
Published
Aug 29, 2026
to the GitHub Advisory Database
•
Updated Aug 30, 2026
Description
Published by the National Vulnerability Database
Aug 29, 2026
Published to the GitHub Advisory Database
Aug 29, 2026
Last updated
Aug 30, 2026
The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate a user-supplied path before using it to build a server-side verification request, and does not verify the authenticity of the response, allowing unauthenticated attackers to redirect that request to an arbitrary host (disclosing the merchant's payment-gateway credentials) and to forge a success response that marks arbitrary WooCommerce orders as paid.
References