PT-2026-71966 · WordPress · Paymob For Woocommerce
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Paymob for WooCommerce versions prior to 4.1.9
Description
An issue exists where a client-supplied identifier is not properly sanitized before being used in a SQL query within the public, unauthenticated payment callback. The query is executed before the payment provider's HMAC signature (a cryptographic hash used to verify data integrity and authenticity) is verified. This allows unauthenticated attackers to perform SQL injection to read arbitrary data from the database, such as user credentials and secrets, using in-band (reflected) and time-based blind extraction techniques.
Recommendations
Update Paymob for WooCommerce to version 4.1.9 or later.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Paymob For Woocommerce