Junglewise Threat Intelligence

CVE-2026-3208: Mercado Pago payments for WooCommerce missing authorization in mp_pix_image API

CVE-2026-3208 · Severity: medium · CVSS 5.3 · Published 2026-05-06

Executive brief

The Mercado Pago payments plugin for WooCommerce, which allows WordPress sites to process payments, contains a security flaw that allows unauthorized access to transaction data. An unauthenticated attacker can view PIX payment QR codes for any order on the site. These QR codes contain sensitive merchant information, including personal identifiers, transaction amounts, and merchant names, which could lead to privacy breaches or targeted fraud.

Technical details

The vulnerability is classified as a missing authorization check (CWE-862) within the 'mp_pix_image' WooCommerce API endpoint. Specifically, the PixGateway.php component fails to validate user permissions before serving PIX payment QR code images. An unauthenticated remote attacker can exploit this by sending requests to the vulnerable endpoint for arbitrary order IDs. Successful exploitation allows the retrieval of QR codes containing sensitive merchant metadata, including PIX keys (CPF/CNPJ identifiers), transaction amounts, and merchant location details. The issue is addressed in version 8.7.12.

Affected products

  • Mercado Pago Mercado Pago payments for WooCommerce up to, and including, 8.7.11

Timeline

  • 2026-05-06: disclosed
  • 2026-05-06: advisory
  • 2026-06-17: patched: Patch confirmed in version 8.7.12 via changeset records.

References