CVE-2026-15205
Received Received - Intake

SQL Injection in Paymob for WooCommerce Plugin

Vulnerability report for CVE-2026-15205, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-14

Last updated on: 2026-08-14

Assigner: WPScan

Description

The Paymob for WooCommerce WordPress plugin before 4.1.9 does not properly sanitise a client-supplied identifier before using it in a SQL query within its public, unauthenticated payment callback, and performs this query before verifying the payment provider's HMAC signature. This allows unauthenticated attackers to perform SQL injection and read arbitrary data from the database β€” including user credentials and other secrets β€” through both in-band (reflected) and time-based blind extraction.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-14
Last Modified
2026-08-14
Generated
2026-08-14
AI Q&A
2026-08-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
paymob paymob_for_woocommerce to 4.1.9 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the Paymob for WooCommerce WordPress plugin before version 4.1.9. It allows unauthenticated attackers to perform SQL injection by exploiting improper sanitization of a client-supplied identifier in a public payment callback. The SQL query runs before verifying the payment provider's HMAC signature, enabling attackers to read arbitrary data from the database, including user credentials.

Detection Guidance

To detect this vulnerability, check the installed version of the Paymob for WooCommerce plugin. If it is below 4.1.9, the system is vulnerable. Use WordPress admin panel or run a command like 'wp plugin list' in the WordPress directory to verify the version.

Impact Analysis

Unauthenticated attackers can exploit this to extract sensitive data like user credentials and other secrets from your database. They can use both in-band and time-based blind SQL injection techniques to access this information without needing to log in.

Compliance Impact

This vulnerability could lead to unauthorized access to personal data, violating GDPR and HIPAA compliance. Exposure of user credentials and other sensitive data may result in regulatory penalties, data breach notifications, and loss of trust.

Mitigation Strategies

Immediately update the Paymob for WooCommerce plugin to version 4.1.9 or later. If updating is not possible, consider disabling the plugin until an update is applied to prevent exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15205. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart