Executive brief
The Paymob payment plugin for WooCommerce, which handles online payments and stored card information for e-commerce stores, fails to verify webhook signatures on its card-token endpoint. An unauthenticated attacker can write fraudulent payment card records to any customer account and discover which accounts exist in the system, potentially enabling fraud or further targeted attacks.
Technical details
The plugin's payment webhook at the card-token branch lacks request signature validation, allowing unauthenticated attackers to forge webhook requests via a network-based attack. This broken access control flaw allows arbitrary card tokens to be written to any user account and enables user enumeration. The vulnerability is fixed in version 4.1.14 and later.
Affected products
- Paymob Paymob for WooCommerce before 4.1.14
Timeline
- 2026-09-23: disclosed
- 2026-09-23: patched: version 4.1.14