PT-2026-95769 · WordPress · Rede Itaú For Woocommerce

CVE-2026-92430

·

Published

2026-09-19

·

Updated

2026-09-19

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit WordPress plugin versions prior to 5.4.7
Description The plugin fails to verify the authenticity of its PIX payment webhook before updating the status of an order. This allows unauthenticated attackers to mark a pending order as paid without completing the actual payment.
Recommendations Update the plugin to version 5.4.7 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92430

Affected Products

Rede Itaú For Woocommerce