CyberRota Analysis
AI-GeneratedThe Payment Gateway for Redsys & WooCommerce Lite plugin for WordPress versions prior to 7.0.2 is vulnerable due to its failure to authenticate incoming payment-provider notifications, enabling attackers to forge payment confirmations. This could allow unauthorized users to mark their orders as paid without actual payment, leading to potential financial losses for merchants. WordPress site administrators using this plugin should prioritize updating to version 7.0.2 or later to mitigate this high-severity risk.
Original NVD Description
The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin before 7.0.2 does not verify the authenticity of incoming payment-provider notifications for one of its payment methods before marking orders as paid, allowing unauthenticated attackers to forge a payment-confirmation callback and complete their own orders without paying.