Sceawere
Vulnerability Detail
CVE-2026-103329UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Super Payments Improper Signature Validation
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 4h ago
- Vendor
- Unknown
- Product
- Super Payments
- Attack Type
- CWE-347 Improper Verification of Cryptographic Signature
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Super Payments WordPress plugin before 1.43.1 does not properly verify the authenticity of incoming payment webhook notifications, as the signing key used to validate their signature is empty by default, allowing unauthenticated attackers to forge a valid signature and mark arbitrary WooCommerce orders as paid without payment.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-10-09T12:17:07.437Z",
"pubdate": "2026-10-09T12:17:07.437Z",
"executiveSummary": "The Super Payments WordPress plugin prior to version 1.43.1 contains a critical vulnerability regarding the verification of incoming webhook notifications.\nThe flaw originates from an improperly initialized cryptographic signing key, which defaults to an empty value during the plugin's operational lifecycle.\nThis vulnerability allows unauthenticated remote attackers to bypass webhook signature verification protocols.\nBy crafting a forged request with an empty key, an attacker can manipulate the payment status of WooCommerce orders.\nThe impact includes financial fraud, as orders can be marked as 'Paid' within the WooCommerce environment without any legitimate transaction processing through the payment gateway.\nThis vulnerability poses a significant risk to e-commerce integrity, as it does not require prior authentication or elevated privileges, and it is accessible over the network via the exposed webhook endpoint.",
"technicalDetails": "The vulnerability stems from an insecure implementation of the webhook verification mechanism within the Super Payments plugin. Webhook notifications are intended to serve as a secure callback mechanism from payment processors, providing confirmation that a transaction has been successfully settled. Typically, these callbacks include an HMAC (Hash-based Message Authentication Code) or a similar cryptographic signature to ensure the authenticity and integrity of the payload.\nIn the affected versions of the Super Payments plugin, the function responsible for validating these incoming notifications fails to implement a robust verification process due to the default use of an empty signing key. Because the secret used to compute or verify the signature is null or empty by default, the signature validation logic effectively evaluates as successful regardless of the payload's origin or content.\nThe attack flow proceeds as follows: First, an attacker identifies a target WooCommerce order ID. Second, the attacker constructs a malicious HTTP POST request mimicking the structure of a legitimate payment gateway webhook notification. Third, because the plugin's validation logic does not enforce a strong, pre-configured secret, the attacker signs the request using the known empty key or exploits the logic error where the verification function defaults to a bypass state.\nUpon receiving this forged payload, the plugin processes the request as a legitimate confirmation of payment. The vulnerable component then updates the WooCommerce order status to 'Paid' or 'Processing' within the database. This manipulation occurs without any actual interaction with the payment processor's infrastructure, effectively bypassing the entire financial transaction flow.\nThis issue is present in all versions prior to 1.43.1. The vulnerability is externally exploitable over the network by any unauthenticated entity capable of reaching the plugin's webhook endpoint. The post-exploitation impact is severe, as it facilitates unauthorized fulfillment of orders and direct financial loss to the merchant through the circumventing of payment requirements."
}