CVE-2026-0692Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The BlueSnap Payment Gateway for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.4.0. This is due to the plugin relying on WooCommerce's `WC_Geolocation::get_ip_address()` function to validate IPN requests, which trusts user-controllable headers like X-Real-IP and X-Forwarded-For to determine the client IP address. This makes it possible for unauthenticated attackers to bypass IP allowlist restrictions by spoofing a whitelisted BlueSnap IP address and send forged IPN (Instant Payment Notification) data to manipulate order statuses (mark orders as paid, failed, refunded, or on-hold) without proper authorization.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-02-14); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-02-14: 3Mentions · 2026-10-05: 1Technical Details · 2026-02-14: 302-1410-05
Signal classification1 categories
Disclosure
3100.0%
Referenced assets4 URLs
Full discourse4 posts
  • pdnuclei-bot@pdnuclei_bot

    🚨 CVE-2026-0692 - high 🚨 BlueSnap Payment Gateway for WooCommerce <=3.4.0 - IPN Authorization Bypass > BlueSnap Payment Gateway for WooCommerce <= 3.4.0 validates its unauthenticated IPN w... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-0692 @pdnuclei #NucleiTempla...

    02011356
    1.3K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-0692 The BlueSnap Payment Gateway for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.3.0. This is due to the… https://www.cve.org/CVERecord?id=CVE-2026-0692

    Post summary

    BlueSnap Payment Gateway for WooCommerce is vulnerable to missing authorization in all versions up to 3.3.0, as identified by CVE‑2026‑0692.

    00010170
    56.5K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-0692 📊 Severity: 7.5 🚨 Risk Level: High 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-0692 #CVE-2026-0692 #CVE #High #Wordpress #CyberSecurity #InfoSec https://t.co/uv7FfBrOke

    Post summary

    The tweet announces a new CVE-2026-0692 vulnerability affecting WordPress, noting its 7.5 severity score and high risk level, but does not provide any proof‑of‑concept, exploit, or patch details.

    0000040
    56 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-0692 BlueSnap Payment Gateway Plugin for WooCommerce Unauthenticated IPN Manipulation https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-0692

    Post summary

    CVE‑2026‑0692 is disclosed as an unauthenticated IPN manipulation vulnerability in the BlueSnap Payment Gateway Plugin for WooCommerce.

    0000032
    4.0K followersView on X

Explore more