Junglewise Threat Intelligence

CVE-2026-16738: Conekta Payment Gateway webhook authentication bypass in WordPress plugin

CVE-2026-16738 · Severity: medium · CVSS 5.3 · Published 2026-08-22

Executive brief

The Conekta Payment Gateway WordPress plugin integrates payment processing from the Conekta payment service into WooCommerce stores. A flaw in versions before 6.2.2 allows attackers to forge payment webhook notifications and mark arbitrary customer orders as paid without actual payment being made, enabling fraud and revenue loss.

Technical details

The plugin receives webhook notifications from the Conekta payment gateway to mark orders as paid but fails to verify the authenticity of incoming webhooks, does not validate that the Conekta order ID matches the WooCommerce order being updated, and does not compare payment amounts. An unauthenticated attacker can send a POST request to the webhook endpoint (/?wc-api=wc_conekta) with a forged payload containing a real paid Conekta order ID (obtained via a single legitimate purchase) and an arbitrary target WooCommerce order number to mark that order as complete. This vulnerability requires the plugin to be installed and configured with valid API keys, but no authentication or CSRF tokens are needed. The attack is repeatable—a single paid Conekta order ID can be reused to complete multiple unrelated orders. The vulnerability is fixed in version 6.2.2.

Affected products

  • Conekta Payment Gateway before 6.2.2

Timeline

  • 2026-08-20: disclosed
  • 2026-08-22: published

References