CVE-2026-92430 PUBLISHED

Rede Itaú for WooCommerce < 5.4.7 - Unauthenticated Order Status Manipulation via PIX Webhook

Assigner: WPScan
Reserved: 16.09.2026 Published: 19.09.2026 Updated: 19.09.2026

The Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit WordPress plugin before 5.4.7 does not verify the authenticity of its PIX payment webhook before updating an order's status, allowing unauthenticated attackers to mark a pending order as paid without paying.

Product Status

Vendor Unknown
Product Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit
Versions Default: unaffected
  • affected from 3.6.1 to 5.4.7 (excl.)

Credits

  • Pablo González Pérez finder
  • Francisco José Ramírez Vicente and Iñigo Sánchez Enciso finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE