{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/payment-gateway/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-5050"}],"_cs_exploited":false,"_cs_has_poc":true,"_cs_poc_references":["https://sploitus.com/exploit?id=1DE20EEC-F6E6-57B9-9E3F-170BF5ECFF94\u0026utm_source=rss\u0026utm_medium=rss"],"_cs_products":["LDAP authentication services"],"_cs_severities":["high"],"_cs_tags":["wordpress","woocommerce","redsys","payment-gateway","vulnerability"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe Payment Gateway for Redsys \u0026amp; WooCommerce Lite plugin, a WordPress plugin enabling integration with Redsys, Bizum, and Google Pay payment gateways, contains a critical vulnerability (CVE-2026-5050) related to improper verification of cryptographic signatures. Specifically, the \u003ccode\u003esuccessful_request()\u003c/code\u003e handlers calculate a local signature but fail to validate the \u003ccode\u003eDs_Signature\u003c/code\u003e parameter from the incoming request. This flaw, present in versions up to and including 7.0.0, allows an unauthenticated attacker with knowledge of a valid order key and amount to manipulate payment status. Successful exploitation results in orders being marked as paid without legitimate payment processing, potentially leading to financial loss for the merchant.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a WordPress site using the vulnerable Payment Gateway for Redsys \u0026amp; WooCommerce Lite plugin (version \u0026lt;= 7.0.0).\u003c/li\u003e\n\u003cli\u003eAttacker places an order on the targeted WooCommerce store, resulting in a pending order.\u003c/li\u003e\n\u003cli\u003eAttacker intercepts the order key and order amount associated with the pending order. This can be obtained via account enumeration.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious HTTP POST request to the WooCommerce payment callback endpoint (e.g., \u003ccode\u003e/wc-api/redsys\u003c/code\u003e). This request contains forged payment data, including a manipulated \u003ccode\u003eDs_Signature\u003c/code\u003e parameter.\u003c/li\u003e\n\u003cli\u003eThe crafted request spoofs a successful payment notification to the \u003ccode\u003esuccessful_request()\u003c/code\u003e handler in the vulnerable plugin.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003esuccessful_request()\u003c/code\u003e handler calculates a local signature but does \u003cem\u003enot\u003c/em\u003e validate the \u003ccode\u003eDs_Signature\u003c/code\u003e parameter in the request.\u003c/li\u003e\n\u003cli\u003eThe plugin incorrectly marks the pending order as \u0026quot;paid\u0026quot; within the WooCommerce system.\u003c/li\u003e\n\u003cli\u003eThe order is processed, and the attacker receives the product or service without completing a legitimate payment.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-5050 allows unauthenticated attackers to bypass payment processes in WooCommerce stores using the vulnerable plugin. This can lead to significant financial losses for affected merchants due to the fulfillment of orders without actual payment. The vulnerability impacts any store running a vulnerable version of the plugin (\u0026lt;= 7.0.0) that uses the Redsys, Bizum, or Google Pay payment gateways. The CVSS v3.1 score is 7.5, indicating a high severity vulnerability.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update the Payment Gateway for Redsys \u0026amp; WooCommerce Lite plugin to the latest version, which contains a fix for CVE-2026-5050.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for suspicious POST requests to the WooCommerce payment callback endpoint (\u003ccode\u003e/wc-api/redsys\u003c/code\u003e) with unusual \u003ccode\u003eDs_Signature\u003c/code\u003e values. Create a rule to detect POST requests to \u003ccode\u003e/wc-api/redsys\u003c/code\u003e with abnormally long or short Ds_Signature parameters.\u003c/li\u003e\n\u003cli\u003eImplement stricter order verification processes in WooCommerce, including manual verification of payment status for suspicious orders.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule to detect HTTP POST requests containing the vulnerable URI and a crafted Ds_Signature field.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-03T04:01:59Z","date_published":"2024-01-02T10:00:00Z","id":"https://feed.craftedsignal.io/briefs/2024-01-redsys-woocommerce-cve-2026-5050/","summary":"The Payment Gateway for Redsys \u0026 WooCommerce Lite plugin for WordPress is vulnerable to cryptographic signature forgery, allowing unauthenticated attackers to mark pending orders as paid by forging payment callback data in versions up to 7.0.0.","title":"WordPress Redsys Payment Gateway Plugin Vulnerable to Payment Forgery (CVE-2026-5050)","url":"https://feed.craftedsignal.io/briefs/2024-01-redsys-woocommerce-cve-2026-5050/"}],"language":"en","title":"CraftedSignal Threat Feed - Payment-Gateway","version":"https://jsonfeed.org/version/1.1"}