Executive brief
Total Processing is a WordPress plugin that handles payment card transactions for WooCommerce online stores. The plugin fails to validate user input and verify responses when communicating with payment gateways, allowing attackers to intercept payment verification requests, steal the merchant's payment gateway credentials, and forge successful payment confirmations for unpaid orders.
Technical details
The plugin contains an unauthenticated Server-Side Request Forgery (SSRF) vulnerability (CWE-918) in its payment verification logic. The vulnerability stems from insufficient input validation of user-supplied paths used to construct verification requests to payment gateways, combined with a failure to verify the authenticity of gateway responses. An unauthenticated attacker can exploit this to redirect the server's verification request to an attacker-controlled host, capturing the merchant's payment gateway credentials in transit, and then forge a successful payment response to mark arbitrary orders as paid without actual payment. The vulnerability is network-accessible and requires no authentication or user interaction. No patch has been publicly disclosed as of the advisory publication date.
Affected products
- Total Processing Card Payments for WooCommerce through 7.3
Timeline
- 2026-08-27: disclosed
- 2026-08-29: advisory