CVE-2026-87981 PUBLISHED

Paymob for WooCommerce < 4.1.14 - Contributor+ Payment Gateway Configuration Deletion and Modification via Multiple AJAX Actions

Assigner: WPScan
Reserved: 09.09.2026 Published: 23.09.2026 Updated: 23.09.2026

The Paymob for WooCommerce WordPress plugin before 4.1.14 does not perform a capability check on several admin AJAX actions that manage its payment-gateway configuration, allowing users with contributor-level access to delete, wipe, or modify that configuration, including the stored payment credentials.

Product Status

Vendor Unknown
Product Paymob for WooCommerce
Versions Default: unaffected
  • affected from 0 to 4.1.14 (excl.)

Credits

  • ryan fabella finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE