Junglewise Threat Intelligence

CVE-2026-87979: Paymob for WooCommerce webhook signature verification bypass

CVE-2026-87979 · Severity: medium · CVSS 5.3 · Published 2026-09-23

Technologies: Paymob for WooCommerce. Vendors: Paymob.

Executive brief

The Paymob payment plugin for WooCommerce, which handles online payments and stored card information for e-commerce stores, fails to verify webhook signatures on its card-token endpoint. An unauthenticated attacker can write fraudulent payment card records to any customer account and discover which accounts exist in the system, potentially enabling fraud or further targeted attacks.

Technical details

The plugin's payment webhook at the card-token branch lacks request signature validation, allowing unauthenticated attackers to forge webhook requests via a network-based attack. This broken access control flaw allows arbitrary card tokens to be written to any user account and enables user enumeration. The vulnerability is fixed in version 4.1.14 and later.

Affected products

  • Paymob Paymob for WooCommerce before 4.1.14

Timeline

  • 2026-09-23: disclosed
  • 2026-09-23: patched: version 4.1.14

References

Related threats