Executive brief
The CorvusPay WooCommerce Payment Gateway plugin for WordPress, which facilitates online payments for e-commerce stores, contains a security flaw that allows unauthenticated users to bypass authentication. This could allow an attacker to perform unauthorized actions that are normally restricted to high-privileged users, potentially leading to administrative access or interference with the store's operations. Business owners should update the plugin immediately to prevent unauthorized access to their site's management functions.
Technical details
The CorvusPay WooCommerce Payment Gateway plugin for WordPress (versions <= 2.7.4) is vulnerable to an authentication bypass via an alternate path or channel (CWE-288). The flaw allows an unauthenticated remote attacker to bypass authentication mechanisms and perform actions that should be restricted to users with higher privileges. According to the advisory, this could lead to a full administrative takeover of the WordPress site. The vulnerability is exploited over the network without requiring user interaction. A fix is available in version 2.7.5.
Affected products
- CorvusPay CorvusPay WooCommerce Payment Gateway <= 2.7.4
Timeline
- 2026-05-08: other: Reported by ParkHyunWoo
- 2026-06-23: disclosed: Initial disclosure by Patchstack
- 2026-06-26: advisory: NVD publication date