Junglewise Threat Intelligence

CVE-2026-66611: Paymob for WooCommerce cross-site scripting in payment forms

CVE-2026-66611 · Severity: high · CVSS 7.1 · Published 2026-08-20

Technologies: Paymob for WooCommerce. Vendors: Paymob.

Executive brief

Paymob for WooCommerce is a WordPress payment gateway plugin that processes online store transactions. The plugin contains an unauthenticated cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into payment pages. When visitors or administrators interact with affected pages, the injected scripts can steal sensitive data, hijack user accounts, or compromise checkout workflows on e-commerce sites.

Technical details

The vulnerability is a stored or reflected cross-site scripting (XSS) flaw in Paymob for WooCommerce versions up to 4.1.10 that does not properly sanitize user-supplied input. An unauthenticated attacker can craft a malicious payload and inject it into vulnerable parameters, which are then executed in the victim's browser without proper escaping or validation. The attack requires user interaction—such as clicking a malicious link or visiting a crafted page—to trigger the payload. Successful exploitation allows the attacker to steal authentication cookies, session tokens, or sensitive payment information. The vulnerability was patched in version 4.1.11 and users should update immediately to mitigate risk.

Affected products

  • Paymob Paymob for WooCommerce <=4.1.10

Timeline

  • 2026-08-20: disclosed
  • 2026-08-19: patched: Version 4.1.11 released

References

Related threats