CVE-2026-16947
Received Received - Intake

Authentication Bypass in Total Processing for WooCommerce

Vulnerability report for CVE-2026-16947, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-29

Last updated on: 2026-08-29

Assigner: WPScan

Description

The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate a user-supplied path before using it to build a server-side verification request, and does not verify the authenticity of the response, allowing unauthenticated attackers to redirect that request to an arbitrary host (disclosing the merchant's payment-gateway credentials) and to forge a success response that marks arbitrary WooCommerce orders as paid.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-29
Last Modified
2026-08-29
Generated
2026-08-29
AI Q&A
2026-08-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
total_processing card_payments_for_woocommerce to 7.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an unauthenticated Server-Side Request Forgery (SSRF) flaw in the Total Processing Card Payments for WooCommerce plugin. It allows attackers to manipulate server-side verification requests by supplying a user-controlled path without validation. The plugin fails to verify response authenticity, enabling redirection to arbitrary hosts to steal payment gateway credentials and forge order payment confirmations.

Detection Guidance

Check if the Total Processing Card Payments for WooCommerce plugin version 7.3 or below is installed. Inspect network traffic for unexpected outbound requests to external hosts from the server. Look for unusual payment gateway credential disclosures or forged order status updates in logs.

Impact Analysis

Attackers could steal your payment gateway credentials, allowing them to intercept or manipulate transactions. They can also mark WooCommerce orders as paid without actual payment, leading to financial losses. Merchants using vulnerable plugin versions are at risk of unauthorized access and fraudulent transactions.

Compliance Impact

This vulnerability could lead to unauthorized access to payment data, violating GDPR's data protection requirements and HIPAA's safeguards for financial information. Merchants may face compliance violations, legal penalties, and reputational damage due to exposed payment credentials and fraudulent transactions.

Mitigation Strategies

Immediately update the plugin to the latest version if available. If no update exists, disable the plugin until a patch is released. Restrict outbound server requests to trusted hosts and monitor network traffic for SSRF attempts. Review order statuses for unauthorized changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16947. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart