Junglewise Threat Intelligence

CVE-2026-9028: CorvusPay WooCommerce Payment Gateway authorization bypass in REST API

CVE-2026-9028 · Severity: medium · CVSS 5.3 · Published 2026-07-09

Technologies: CorvusPay WooCommerce Payment Gateway. Vendors: CorvusPay.

Executive brief

The CorvusPay WooCommerce Payment Gateway plugin for WordPress, which allows online stores to process payments, contains a security flaw that allows unauthorized individuals to cancel customer orders. By sending a specific request to the website, an attacker can cancel any order processed through CorvusPay without needing to log in. This could lead to significant operational disruption and loss of revenue for affected merchants.

Technical details

The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to a missing authorization check (CWE-862) in all versions up to and including 2.7.4. The vulnerability exists within the REST API endpoint `/wp-json/corvuspay/cancel/`, which fails to verify if the requester has the appropriate permissions to modify order statuses. An unauthenticated remote attacker can exploit this by providing an arbitrary order number to the endpoint, resulting in the cancellation of that specific WooCommerce order. This issue was addressed in version 2.7.5 or later via a changeset that implemented proper authorization checks.

Affected products

  • CorvusPay CorvusPay WooCommerce Payment Gateway Up to, and including, 2.7.4

Timeline

  • 2026-07-09: disclosed
  • 2026-07-09: advisory

References

Related threats