CVE-2026-103329
Super Payments < 1.43.1 - Unauthenticated Payment Confirmation Forgery via Webhook Signature
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
The Super Payments WordPress plugin before 1.43.1 does not properly verify the authenticity of incoming payment webhook notifications, as the signing key used to validate their signature is empty by default, allowing unauthenticated attackers to forge a valid signature and mark arbitrary WooCommerce orders as paid without payment.
| Vendor | unknown |
| Product | super payments |
| Published | Oct 9, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown super payments
Be the first to know when new medium vulnerabilities affecting unknown super payments are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
Unknown / Super Payments
0 < 1.43.1
References
Credits
Naoki Kawahigashi WPScan