SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-16947

CRITICAL · CVSS 9.1 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-08-29 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The Total processing card payments for WooCommerce plugin in WordPress is vulnerable due to inadequate validation of user-supplied paths, enabling unauthenticated attackers to redirect server-side verification requests to arbitrary hosts. This flaw can lead to the disclosure of merchant payment-gateway credentials and allow attackers to forge success responses, falsely marking WooCommerce orders as paid. WordPress site administrators using this plugin should prioritize addressing this vulnerability to protect sensitive payment information and maintain order integrity.

CVE
CVE-2026-16947
Severity
CRITICAL
CVSS
9.1
EPSS
0.24%
WordPress

Original NVD Description

The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate a user-supplied path before using it to build a server-side verification request, and does not verify the authenticity of the response, allowing unauthenticated attackers to redirect that request to an arbitrary host (disclosing the merchant's payment-gateway credentials) and to forge a success response that marks arbitrary WooCommerce orders as paid.