PT-2026-71966 · WordPress · Paymob For Woocommerce

·

CVE-2026-15205

·

Published

2026-08-14

·

Updated

2026-08-14

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Paymob for WooCommerce versions prior to 4.1.9
Description An issue exists where a client-supplied identifier is not properly sanitized before being used in a SQL query within the public, unauthenticated payment callback. The query is executed before the payment provider's HMAC signature (a cryptographic hash used to verify data integrity and authenticity) is verified. This allows unauthenticated attackers to perform SQL injection to read arbitrary data from the database, such as user credentials and secrets, using in-band (reflected) and time-based blind extraction techniques.
Recommendations Update Paymob for WooCommerce to version 4.1.9 or later.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15205

Affected Products

Paymob For Woocommerce