CVE-2026-92430 - Rede Itaú for WooCommerce < 5.4.7 - Unauthenticated Order Status Manipulation via PIX Webhook
CVE ID :CVE-2026-92430
Published : Sept. 19, 2026, 6 a.m. | 1 hour, 8 minutes ago
Description :The Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit WordPress plugin before 5.4.7 does not verify the authenticity of its PIX payment webhook before updating an order's status, allowing unauthenticated attackers to mark a pending order as paid without paying.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 19, 2026, 6 a.m. | 1 hour, 8 minutes ago
Description :The Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit WordPress plugin before 5.4.7 does not verify the authenticity of its PIX payment webhook before updating an order's status, allowing unauthenticated attackers to mark a pending order as paid without paying.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...