CVE-2026-87979
Paymob for WooCommerce < 4.1.14 - Unauthenticated Saved Card Token Write to Any User via Webhook
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Paymob for WooCommerce WordPress plugin before 4.1.14 does not verify the request signature on the card-token branch of its payment webhook, allowing unauthenticated attackers to write a card-token record to any user's account and to enumerate registered accounts.
| Vendor | unknown |
| Product | paymob for woocommerce |
| Published | Sep 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown paymob for woocommerce
Be the first to know when new unknown vulnerabilities affecting unknown paymob for woocommerce are published β delivered to Slack, Telegram or Discord.
Get Free Alerts β
Free Β· No credit card Β· 60 sec setup
Affected Versions
Unknown / Paymob for WooCommerce
0 < 4.1.14
References
Credits
SalΓΊa Es-sair WPScan