CVE WATCH / VULNERABILITY DETAIL

CVE-2026-103329

MEDIUMCVSS 5.3NVD feed

Published 9 October 2026 · tracked since 10 October 2026

Description

The Super Payments WordPress plugin before 1.43.1 does not properly verify the authenticity of incoming payment webhook notifications, as the signing key used to validate their signature is empty by default, allowing unauthenticated attackers to forge a valid signature and mark arbitrary WooCommerce

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-103329 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-103329

MEDIUMCVSS 5.3NVD feed

Published 9 October 2026 · tracked since 10 October 2026

Description

The Super Payments WordPress plugin before 1.43.1 does not properly verify the authenticity of incoming payment webhook notifications, as the signing key used to validate their signature is empty by default, allowing unauthenticated attackers to forge a valid signature and mark arbitrary WooCommerce

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]