Unauthenticated Bypass Vulnerability in Pay With MetaMask for WooCommerce Plugin
CVE-2026-107420
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 October 2026
What is CVE-2026-107420?
The Pay With MetaMask for WooCommerce plugin for WordPress has a vulnerability that allows attackers to bypass authentication. This flaw affects version 1.7.2 and below, potentially enabling unauthorized access to sensitive functionalities within the plugin, posing significant risks for e-commerce sites using cryptocurrency payments. It is crucial for users to update to the latest version to mitigate exploitation risks.
Affected Version(s)
Pay With MetaMask For WooCommerce β Cryptocurrency Payment Gateway <= 1.7.2