Junglewise Threat Intelligence

CVE-2026-87981: Paymob for WooCommerce AJAX actions missing capability check

CVE-2026-87981 · Severity: medium · CVSS 4.7 · Published 2026-09-23

Technologies: Paymob for WooCommerce. Vendors: Paymob.

Executive brief

The Paymob for WooCommerce payment gateway plugin fails to verify user permissions on several administrative actions, allowing users with basic contributor-level access to delete or modify the plugin's payment configuration, including stored payment credentials. This could lead to disruption of payment processing, data theft, or configuration tampering by low-privileged attackers.

Technical details

Multiple admin AJAX actions lack capability checks, violating the principle of least privilege. An unauthenticated or low-privileged attacker can invoke these actions over the network to delete, wipe, or modify payment gateway settings. The vulnerability affects versions before 4.1.14 and is classified as broken access control (CWE-862).

Affected products

  • Paymob Paymob for WooCommerce before 4.1.14

Timeline

  • 2026-09-21: disclosed
  • 2026-09-23: patched: Fixed in version 4.1.14

References

Related threats