CVE WATCH / VULNERABILITY DETAIL
CVE-2026-103329
MEDIUMCVSS 5.3NVD feed
Published 9 October 2026 · tracked since 10 October 2026
Description
The Super Payments WordPress plugin before 1.43.1 does not properly verify the authenticity of incoming payment webhook notifications, as the signing key used to validate their signature is empty by default, allowing unauthenticated attackers to forge a valid signature and mark arbitrary WooCommerce
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-107804 MEDIUM 5.3
- CVE-2026-107805 HIGH 7.5
- CVE-2026-105278 CRITICAL 9.8
- CVE-2026-104081 HIGH 8.1
- CVE-2026-94067 HIGH 8.1
- CVE-2026-94064 HIGH 8.8
- CVE-2026-94065 HIGH 8.8
- CVE-2026-100730 CRITICAL 9.8
- CVE-2026-94062 HIGH 8.1
- CVE-2026-62028 MEDIUM 5.4