Executive brief
The Wizit Gateway for WooCommerce plugin, used to process payments in WooCommerce stores, fails to verify user identity before allowing order cancellations. An attacker can cancel any customer order without authentication by sending a specially crafted request, disrupting sales operations and customer experience.
Technical details
This is an authorization bypass vulnerability in the 'handle_checkout_redirecturl_response' function of the Wizit Gateway for WooCommerce plugin. The vulnerable function lacks proper authentication and authorization checks, allowing unauthenticated attackers to cancel arbitrary WooCommerce orders by sending a crafted HTTP request with a valid order ID. The vulnerability is triggered via the plugin's webhook/redirect handling mechanism. No special privileges or user interaction are required to exploit this vulnerability.
Affected products
- Wizit Gateway for WooCommerce 1.3.1 and prior
Timeline
- 2026-01-24: disclosed