Executive brief
The Paymob for WooCommerce plugin, which enables online payment processing for WordPress stores, contains a security flaw that allows unauthorized individuals to perform actions they should not have access to. This could potentially allow an attacker to interfere with order processing or modify transaction data without needing to log in. Such an exploit could disrupt business operations and compromise the integrity of the store's payment workflow.
Technical details
The Paymob for WooCommerce plugin for WordPress suffers from a broken access control vulnerability (CWE-862) due to missing authorization checks in certain functions. This allows an unauthenticated remote attacker to execute actions that should be restricted to higher-privileged users. The vulnerability is exploitable over the network without any user interaction. While the specific impacted functions are not detailed in the advisory, the CVSS vector indicates a high impact on integrity (I:H) with no impact on confidentiality or availability. As of the advisory date, no official patch has been released.
Affected products
- Paymob Paymob for WooCommerce <= 4.1.2
Timeline
- 2026-05-06: other: Vulnerability reported by researcher Sajjad Haqi
- 2026-06-19: advisory: Initial advisory published by Patchstack
- 2026-06-26: disclosed: CVE published to NVD