Web Application Vulnerability in Super Payments for WooCommerce by WordPress
CVE-2026-103329
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 9 October 2026
Badges
What is CVE-2026-103329?
The Super Payments plugin for WooCommerce does not adequately authenticate payment webhook notifications. This flaw arises because the signing key used for signature validation is empty by default. Consequently, this allows malicious actors to create valid signatures, enabling them to indicate that WooCommerce orders have been marked as paid without actual payment being processed. Implementing proper validation protocols and ensuring the signing key is configured correctly is essential to mitigate this vulnerability.
Affected Version(s)
Super Payments 0 < 1.43.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved