Executive brief
A security vulnerability exists in the NOWPayments plugin for WooCommerce, which is used by online stores to accept cryptocurrency payments. An unauthorized attacker could exploit this flaw to bypass security checks and perform actions they should not have permission to do, such as modifying payment statuses or order details. This could lead to financial discrepancies or unauthorized changes to customer transactions.
Technical details
The NOWPayments for WooCommerce plugin (versions 1.4.0 and below) is vulnerable to broken access control due to missing authorization (CWE-862). The vulnerability allows an unauthenticated remote attacker to execute functions that should be restricted to privileged users. According to the CVSS vector, the attack is low complexity and requires no user interaction, primarily impacting the integrity of the system. As of the advisory date, no official patch has been released.
Affected products
- CoderPress NOWPayments for WooCommerce <= 1.4.0
Timeline
- 2026-01-19: disclosed: Reported by b4shu206 to Patchstack
- 2026-06-29: advisory: Initial advisory published by Patchstack
- 2026-07-02: advisory: NVD publication date