AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-12584

HIGH · CVSS 7.5 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Payment Gateway for Redsys & WooCommerce Lite plugin for WordPress versions prior to 7.0.2 is vulnerable due to its failure to authenticate incoming payment-provider notifications, enabling attackers to forge payment confirmations. This could allow unauthorized users to mark their orders as paid without actual payment, leading to potential financial losses for merchants. WordPress site administrators using this plugin should prioritize updating to version 7.0.2 or later to mitigate this high-severity risk.

CVE
CVE-2026-12584
Severity
HIGH
CVSS
7.5
EPSS
0.18%
WordPress

Original NVD Description

The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin before 7.0.2 does not verify the authenticity of incoming payment-provider notifications for one of its payment methods before marking orders as paid, allowing unauthenticated attackers to forge a payment-confirmation callback and complete their own orders without paying.