Executive brief
A security vulnerability exists in the Redsys for WooCommerce Light plugin, which is used by WordPress sites to process credit card payments. An unauthorized person could bypass security checks to perform actions they should not be allowed to do, potentially interfering with order processing or payment status. This could lead to unauthorized changes in transaction records or business operations.
Technical details
The Redsys for WooCommerce Light plugin for WordPress (versions up to and including 7.0.0) suffers from a broken access control vulnerability due to missing authorization checks (CWE-862). This flaw allows an unauthenticated remote attacker to execute functions that should be restricted to higher-privileged users or internal processes. The vulnerability has a CVSS score of 7.5, primarily impacting integrity as attackers can modify data without proper permission. The issue is resolved in version 7.0.1.
Affected products
- Redsys Redsys for WooCommerce Light <= 7.0.0
Timeline
- 2026-02-14: other: Reported by Nguyen Ba Khanh
- 2026-04-16: patched: Version 7.0.1 released
- 2026-06-15: disclosed: CVE published to NVD