WordPress · Paymob For Woocommerce · CVE-2026-87979
**Name of the Vulnerable Software and Affected Versions**
Paymob for WooCommerce WordPress plugin versions prior to 4.1.14
**Description**
The plugin fails to verify the request signature within the card-token branch of its payment webhook. This flaw allows unauthenticated attackers to enumerate registered accounts and write a card-token record to any user account.
**Recommendations**
Update the Paymob for WooCommerce WordPress plugin to version 4.1.14 or later.