CVE-2026-103329
Received Received - Intake

Super Payments Plugin Webhook Signature Bypass

Vulnerability report for CVE-2026-103329, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: WPScan

Description

The Super Payments WordPress plugin before 1.43.1 does not properly verify the authenticity of incoming payment webhook notifications, as the signing key used to validate their signature is empty by default, allowing unauthenticated attackers to forge a valid signature and mark arbitrary WooCommerce orders as paid without payment.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown Super Payments 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Super Payments WordPress plugin before version 1.43.1 has a flaw where it does not verify the authenticity of payment webhook notifications properly. The signing key used to validate these notifications is empty by default, allowing attackers to forge valid signatures. This lets them mark WooCommerce orders as paid without actual payment.

Detection Guidance

Check if the Super Payments WordPress plugin is installed and verify its version. If it is below 1.43.1, the system is vulnerable. Use WordPress admin panel or run commands like 'wp plugin list' in the WordPress directory to check the plugin version.

Impact Analysis

Unauthenticated attackers can exploit this to trick the system into marking orders as paid without real transactions. This could lead to financial losses, incorrect order fulfillment, and potential disruption of business operations.

Compliance Impact

This vulnerability could impact compliance by allowing unauthorized transactions, which may violate data integrity and financial reporting requirements in standards like GDPR or HIPAA. Proper order validation is critical for audit trails and regulatory adherence.

Mitigation Strategies

Update the Super Payments plugin to version 1.43.1 or later immediately. If updating is not possible, consider disabling the plugin temporarily until an update is applied. Monitor WooCommerce orders for unauthorized payment confirmations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103329. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart