Admin AJAX Actions Vulnerability in Paymob for WooCommerce WordPress Plugin
CVE-2026-87981
Currently unrated
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 23 September 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-87981?
The Paymob for WooCommerce plugin for WordPress prior to version 4.1.14 contains a significant access control flaw that lacks appropriate capability checks on multiple admin AJAX actions. This oversight enables users with contributor-level permissions to delete, modify, or erase critical payment-gateway configurations, compromising stored payment credentials and posing a serious threat to site security. Website administrators must update to the latest version to mitigate this vulnerability.
Affected Version(s)
Paymob for WooCommerce 0 < 4.1.14
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.