Junglewise Threat Intelligence

CVE-2026-39645: Global Payments GlobalPayments WooCommerce SSRF

CVE-2026-39645 · Severity: medium · CVSS 5.4 · Published 2026-04-08

Executive brief

The GlobalPayments WooCommerce plugin for WordPress, which facilitates credit card processing for online stores, contains a security flaw that allows unauthorized requests to be sent from the web server. An attacker could exploit this to probe internal network services or access sensitive information that is not normally exposed to the internet. While the risk is considered moderate, it could lead to data exposure or be used as a stepping stone for further attacks on the internal infrastructure.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the GlobalPayments WooCommerce plugin for WordPress (versions <= 1.18.3). The flaw allows unauthenticated remote attackers to induce the server to make requests to arbitrary domains or internal network resources. This is typically caused by insufficient validation of user-supplied URLs before they are processed by the server's backend. An attacker can leverage this to perform internal port scanning, bypass firewalls, or access metadata services in cloud environments. The vulnerability is addressed in version 1.18.4.

Affected products

  • Global Payments GlobalPayments WooCommerce <= 1.18.3

Timeline

  • 2026-01-16: other: Reported by Nguyen Ba Khanh
  • 2026-02-15: disclosed: Vulnerability disclosed by Patchstack
  • 2026-02-15: patched: Version 1.18.4 released to address the issue
  • 2026-04-08: advisory: CVE published

References