CVE-2026-56029
Deferred Deferred - Pending Action
Unauthenticated Broken Authentication in CorvusPay WooCommerce Payment Gateway

Publication date: 2026-06-26

Last updated on: 2026-06-26

Assigner: Patchstack

Description
Unauthenticated Broken Authentication in CorvusPay WooCommerce Payment Gateway <= 2.7.4 versions.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-26
Last Modified
2026-06-26
Generated
2026-06-26
AI Q&A
2026-06-26
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
corvuspay woocommerce_payment_gateway to 2.7.4 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-288 The product requires authentication, but the product has an alternate path or channel that does not require authentication.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

The CorvusPay WooCommerce Payment Gateway Plugin versions 2.7.4 and below contain a Broken Authentication vulnerability (CVE-2026-56029). This flaw allows unauthenticated attackers to perform actions that are normally restricted to users with higher privileges, potentially enabling them to gain administrative access.

This vulnerability is classified under the OWASP Top 10 category A7: Identification and Authentication Failures.

Impact Analysis

An attacker exploiting this vulnerability can gain unauthorized administrative access to the affected WooCommerce payment gateway plugin. This could allow them to manipulate payment processes, access sensitive data, or perform other malicious actions within the system.

The vulnerability has a CVSS severity score of 7.5, indicating a high impact on the integrity of the system, though it does not affect confidentiality or availability.

Mitigation Strategies

The vulnerability affects CorvusPay WooCommerce Payment Gateway Plugin versions 2.7.4 and below.

To mitigate this vulnerability, immediately update the plugin to version 2.7.5 or later where the issue is patched.

Alternatively, seek assistance from your hosting provider or developer to apply the necessary fixes.

If you use Patchstack, enable auto-updates for vulnerable plugins to ensure timely patching.

Compliance Impact

The vulnerability in CorvusPay WooCommerce Payment Gateway Plugin allows unauthenticated attackers to perform actions typically restricted to higher-privileged users, potentially gaining admin access. This broken authentication issue falls under the OWASP Top 10 category A7: Identification and Authentication Failures.

Such unauthorized access can lead to improper handling or exposure of sensitive data, which may impact compliance with standards and regulations like GDPR and HIPAA that require strict access controls and protection of personal and health information.

Therefore, if exploited, this vulnerability could compromise the confidentiality and integrity of data, potentially resulting in non-compliance with these regulations.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-56029. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart